Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade exim | Nov 8, 2019 | Sep 27, 2019 |
| Amazon_linux | — | Upgrade exim | Oct 26, 2019 | Sep 27, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Sep 27, 2019 |
| Debian | — | Upgrade exim4 | Sep 30, 2019 | Sep 30, 2019 |
| Exim | — | Upgrade Exim to version 4.92.2 | Sep 30, 2019 | Sep 27, 2019 |
| Gentoo Linux | — | Upgrade mail-mta/exim. | Mar 23, 2020 | Sep 27, 2019 |
| Suse | — | Upgrade eximstats-htmlUpgrade eximonUpgrade libspf2-develUpgrade libspf2-toolsUpgrade eximUpgrade libspf2-2 | May 8, 2021 | Sep 27, 2019 |
| Ubuntu | — | Upgrade exim4-daemon-heavyUpgrade exim4-daemon-light | Sep 29, 2019 | Sep 27, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub