CVE-2019-10149: critical vulnerability in exim
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
Exim email servers versions 4.87 to 4.91 fail to properly validate recipient addresses, allowing attackers to execute arbitrary commands on the server remotely.
A command injection vulnerability exists in the deliver_message() function within /src/deliver.c where insufficient input validation on recipient addresses permits unauthenticated remote code execution. The attack vector requires sending a specially crafted email with a malicious recipient address; exploitation is trivial as Exim processes untrusted input directly in shell contexts.
The full analysis of this CVE is available in Portuguese →