CVE-2019-13917: Critical severity sa-exim vulnerability
Published Jul 25, 2019
·Updated
Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $localpart or $domain).
Affected Software
4 affected componentsFixes available
debian/exim4
4.92-8+deb10u64.92-8+deb10u84.94.2-74.94.2-7+deb11u14.96-15+deb12u14.96-15+deb12u24.97~RC2-2
Exim Exim>=4.85<=4.92
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Remediation
Patch Available
Event History
Jul 25, 2019
CVE Published
via MITRE·07:07 PM
Data Sourced
via MITRE·07:07 PM
Description
Frequently Asked Questions
1
What is CVE-2019-13917?
CVE-2019-13917 is a vulnerability in Exim 4.85 through 4.92 that allows remote code execution as root in certain configurations.
2
What is the severity of CVE-2019-13917?
CVE-2019-13917 has a severity rating of critical (9.8).
3
How does CVE-2019-13917 allow remote code execution?
CVE-2019-13917 allows remote code execution by exploiting certain configurations that use the ${sort } expansion for controllable items, such as $local_part or $domain.
4
Which versions of Exim are affected by CVE-2019-13917?
Exim versions 4.85 through 4.92 are affected by CVE-2019-13917.
5
How can I fix CVE-2019-13917?
The vulnerability has been fixed in Exim version 4.92.1, so updating to this version or later will fix the issue.