CVE-2019-10149
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Exim Mail Transfer Agent (MTA) Improper Input Validation
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-11/8/2026
- CWE
- CWE-78
מוצרים מושפעים
exim: exim; canonical: ubuntu linux; debian: debian linux
קישורים
- https://www.exim.org/static/doc/security/CVE-2019-10149.txt Vendor Advisory
- https://www.exim.org/static/doc/security/CVE-2019-10149.txt Vendor Advisory
- http://www.openwall.com/lists/oss-security/2019/06/05/3 Mailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/06/05/3 Mailing ListPatchThird Party Advisory
- http://packetstormsecurity.com/files/153218/Exim-4.9.1-Remote-Command-Executio… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/153312/Exim-4.91-Local-Privilege-Escalati… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/154198/Exim-4.91-Local-Privilege-Escalati… ExploitThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2019/06/05/4 ExploitMailing List
- http://www.openwall.com/lists/oss-security/2019/06/06/1 ExploitMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/153218/Exim-4.9.1-Remote-Command-Executio… ExploitThird Party AdvisoryVDB Entry