Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-13917

Опубликовано: 25 июл. 2019
Источник: debian
EPSS Средний

Описание

Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $local_part or $domain).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
exim4fixed4.92-10package
exim4not-affectedjessiepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2019/07/22/3

  • https://www.exim.org/static/doc/security/CVE-2019-13917.txt

  • https://git.exim.org/exim.git/commit/21aa05977abff1eaa69bb97ef99080220915f7c0

EPSS

Процентиль: 95%
0.19865
Средний

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $local_part or $domain).

CVSS3: 8.1
redhat
больше 6 лет назад

Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $local_part or $domain).

CVSS3: 9.8
nvd
больше 6 лет назад

Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $local_part or $domain).

CVSS3: 9.8
github
больше 3 лет назад

Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $local_part or $domain).

CVSS3: 9.8
fstec
больше 6 лет назад

Уязвимость почтового сервера Exim, связанная с ошибками обработки объектов в памяти позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

EPSS

Процентиль: 95%
0.19865
Средний