CVE-2019-13917
9.8
CRITICAL · CVSS 3.0 · EPSS 8.6% (pctl 95)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $local_part or $domain).
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 8.62% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-19 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-07-25 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| debian | debian linux |
| exim | exim |
References
- http://exim.org/static/doc/security/CVE-2019-13917.txt
- http://www.openwall.com/lists/oss-security/2019/07/26/5
- https://seclists.org/bugtraq/2019/Jul/51
- https://security.gentoo.org/glsa/201909-06
- https://www.debian.org/security/2019/dsa-4488
- http://exim.org/static/doc/security/CVE-2019-13917.txt
- http://www.openwall.com/lists/oss-security/2019/07/26/5
- https://seclists.org/bugtraq/2019/Jul/51
- https://security.gentoo.org/glsa/201909-06
- https://www.debian.org/security/2019/dsa-4488
→ the Explorer · watch your stack · NVD