Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-exim | Nov 8, 2019 | Sep 27, 2019 | |
| Amazon_linux | — | amazon-linux-upgrade-exim | Oct 26, 2019 | Sep 27, 2019 |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Sep 27, 2019 | |
| Debian | debian-upgrade-exim4 | Sep 30, 2019 | Sep 30, 2019 | |
| Exim | exim-upgrade-latest | Sep 30, 2019 | Sep 27, 2019 | |
| Gentoo Linux | gentoo-linux-upgrade-mail-mta-exim | Mar 23, 2020 | Sep 27, 2019 | |
| Suse | — | suse-upgrade-eximsuse-upgrade-eximonsuse-upgrade-eximstats-htmlsuse-upgrade-libspf2-2suse-upgrade-libspf2-develsuse-upgrade-libspf2-tools | May 8, 2021 | Sep 27, 2019 |
| Ubuntu | ubuntu-upgrade-exim4-daemon-heavyubuntu-upgrade-exim4-daemon-light | Sep 29, 2019 | Sep 27, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub