A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00020.html
http://packetstormsecurity.com/files/153218/Exim-4.9.1-Remote-Command-Execution.html
http://packetstormsecurity.com/files/153312/Exim-4.91-Local-Privilege-Escalation.html
http://packetstormsecurity.com/files/154198/Exim-4.91-Local-Privilege-Escalation.html
http://seclists.org/fulldisclosure/2019/Jun/16
http://www.openwall.com/lists/oss-security/2019/06/05/2
http://www.openwall.com/lists/oss-security/2019/06/05/3
http://www.openwall.com/lists/oss-security/2019/06/05/4
http://www.openwall.com/lists/oss-security/2019/06/06/1
http://www.openwall.com/lists/oss-security/2019/07/25/6
http://www.openwall.com/lists/oss-security/2019/07/25/7
http://www.openwall.com/lists/oss-security/2019/07/26/4
http://www.securityfocus.com/bid/108679
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10149
https://seclists.org/bugtraq/2019/Jun/5
https://security.gentoo.org/glsa/201906-01
https://usn.ubuntu.com/4010-1/
Source: MITRE
Published: 2019-06-05
Updated: 2019-06-11
Type: CWE-20
Base Score: 7.5
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
Impact Score: 6.4
Exploitability Score: 10
Severity: HIGH
Base Score: 9.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 3.9
Severity: CRITICAL
OR
cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:* versions from 4.87 to 4.91 (inclusive)
ID | Name | Product | Family | Severity |
---|---|---|---|---|
127100 | Exim deliver_message() Function Remote Command Execution Vulnerability (Remote) | Nessus | SMTP problems | high |
125843 | openSUSE Security Update : exim (openSUSE-2019-1524) | Nessus | SuSE Local Security Checks | high |
125770 | Ubuntu 18.04 LTS / 18.10 : exim4 vulnerability (USN-4010-1) | Nessus | Ubuntu Local Security Checks | high |
125751 | GLSA-201906-01 : Exim: Remote command execution | Nessus | Gentoo Local Security Checks | high |
125749 | FreeBSD : Exim -- RCE in deliver_message() function (45bea6b5-8855-11e9-8d41-97657151f8c2) | Nessus | FreeBSD Local Security Checks | high |
125742 | Debian DSA-4456-1 : exim4 - security update | Nessus | Debian Local Security Checks | high |
125739 | Amazon Linux AMI : exim (ALAS-2019-1221) | Nessus | Amazon Linux Local Security Checks | high |
700728 | Exim < 4.92 RCE | Nessus Network Monitor | SMTP Servers | high |
125737 | Exim 4.87 < 4.92 Remote Command Execution | Nessus | SMTP problems | high |