ZeroHour

CVE-2019-16928

KEV PoC ×2

Exim Out-of-bounds Write Vulnerability

CVSS 3.1
9.8 critical
EPSS
42%p99
Published
()
KEV added
Description

Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.

CISA Known Exploited Vulnerability
Affected
Exim Exim Internet Mailer
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
eximcanonicaldebianfedoraproject
Products
exim, ubuntu linux, debian linux, fedora
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news