CVE-2019-15846: Critical severity Exim Exim vulnerability
Published Sep 6, 2019
·Updated
Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.
Affected Software
5 affected componentsFixes available
Exim Exim<4.92.2
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
debian/exim4
4.94.2-7+deb11u34.94.2-7+deb11u44.96-15+deb12u74.98.2-14.99.1-1
Remediation
Mitigation
Add - as part of the mail ACL (the ACL referenced by the main config
option "acl_smtp_mail"):
deny condition = ${if eq{\\}{${substr{-1}{1}{$tls_in_sni}}}}
deny condition = ${if eq{\\}{${substr{-1}{1}{$tls_in_peerdn}}}}
Event History
Sep 6, 2019
CVE Published
via MITRE·10:15 AM
Data Sourced
via MITRE·10:15 AM
Description
Data Sourced
via NVD·11:15 AM
DescriptionSeverityAffected Software
Feb 20, 2026
Data Sourced
via Ubuntu·11:43 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·11:44 PM
Description
Data Sourced
via Debian·11:44 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2019-15846?
CVE-2019-15846 is a vulnerability in Exim, a popular mail transfer agent, that allows remote attackers to execute arbitrary code as root.
2
What is the severity of CVE-2019-15846?
The severity of CVE-2019-15846 is critical with a CVSS score of 9.8.
3
Which software versions are affected by CVE-2019-15846?
The affected software versions are Exim versions before 4.92.2.
4
How can I fix CVE-2019-15846?
To fix CVE-2019-15846, you should update Exim to version 4.92.2 or higher.
5
Where can I find more information about CVE-2019-15846?
You can find more information about CVE-2019-15846 on the following references: [1] http://exim.org/static/doc/security/CVE-2019-15846.txt [2] http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00024.html [3] http://www.openwall.com/lists/oss-security/2019/09/06/2