CVE-2019-10149: Exim Mail Transfer Agent (MTA) Improper Input Validation
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in delivermessage() function in /src/deliver.c may lead to remote command execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/exim4to a version that resolves this vulnerability.Fixed in 4.94.2-7+deb11u3Fixed in 4.94.2-7+deb11u6Fixed in 4.96-15+deb12u10Fixed in 4.98.2-1+deb13u3Fixed in 4.98.2-1+deb13u4Fixed in 4.99.4-2
Event History
Frequently Asked Questions
What is CVE-2019-10149?
CVE-2019-10149 is a vulnerability in the Exim Mail Transfer Agent (MTA) that allows remote command execution.
What is the severity of CVE-2019-10149?
CVE-2019-10149 has a severity rating of 9.8, which is considered critical.
How does CVE-2019-10149 affect Exim?
CVE-2019-10149 affects Exim versions 4.87 to 4.91 (inclusive).
How can CVE-2019-10149 be exploited?
CVE-2019-10149 can be exploited through improper validation of recipient address, leading to remote command execution.
Is there a fix available for CVE-2019-10149?
Yes, the fix for CVE-2019-10149 is available in specific versions of Exim and Debian/Ubuntu Linux.