Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-16928

Опубликовано: 27 сент. 2019
Источник: redhat
CVSS3: 9.8
EPSS Критический

Описание

Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.

A heap-based buffer overflow flaw was found in Exim. The overflow can be triggered via specially crafted SMTP-protocol EHLO message, which may lead to unauthenticated remote code execution. It is thought that the execution of the remote code would be at the exim user level although execution as the root user cannot be ruled out.

Отчет

This issue did not affect Red Hat Enterprise Linux 5 as the exim package did not contain the vulnerable code in any of our supported products.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5eximNot affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-119->CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1756930exim: remotely triggerable buffer overflow in string_vformat()

EPSS

Процентиль: 100%
0.90014
Критический

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.

CVSS3: 9.8
nvd
больше 6 лет назад

Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.

CVSS3: 9.8
debian
больше 6 лет назад

Exim 4.92 through 4.92.2 allows remote code execution, a different vul ...

CVSS3: 9.8
github
больше 3 лет назад

Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.

CVSS3: 9.8
fstec
больше 6 лет назад

Уязвимость компонента string_vformat (string.c) почтового сервера Exim, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код

EPSS

Процентиль: 100%
0.90014
Критический

9.8 Critical

CVSS3