Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade exim | Nov 8, 2019 | Sep 27, 2019 |
| Amazon_linux | — | Upgrade exim | Oct 26, 2019 | Sep 27, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Sep 27, 2019 |
| Debian | — | Upgrade exim4 | Sep 30, 2019 | Sep 30, 2019 |
| Exim | — | Upgrade Exim to version 4.92.2 | Sep 30, 2019 | Sep 27, 2019 |
| Gentoo Linux | — | Upgrade mail-mta/exim. | Mar 23, 2020 | Sep 27, 2019 |
| Suse | — | Upgrade libspf2-2Upgrade eximUpgrade libspf2-toolsUpgrade eximonUpgrade eximstats-htmlUpgrade libspf2-devel | May 8, 2021 | Sep 27, 2019 |
| Ubuntu | — | Upgrade exim4-daemon-lightUpgrade exim4-daemon-heavy | Sep 29, 2019 | Sep 27, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub