Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-10149

A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.939
EPSS Ranking 99.9%
CVSS Severity
CVSS v3 Score 9.0
CVSS v2 Score 10.0
Proposed Action
Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
Ransomware Campaign
Unknown
References
Products affected by CVE-2019-10149
  • Exim » Exim » Version: 4.87
    cpe:2.3:a:exim:exim:4.87
  • Exim » Exim » Version: 4.87.1
    cpe:2.3:a:exim:exim:4.87.1
  • Exim » Exim » Version: 4.88
    cpe:2.3:a:exim:exim:4.88
  • Exim » Exim » Version: 4.89
    cpe:2.3:a:exim:exim:4.89
  • Exim » Exim » Version: 4.89.1
    cpe:2.3:a:exim:exim:4.89.1
  • Exim » Exim » Version: 4.90
    cpe:2.3:a:exim:exim:4.90
  • Exim » Exim » Version: 4.90.0.22
    cpe:2.3:a:exim:exim:4.90.0.22
  • Exim » Exim » Version: 4.90.0.27
    cpe:2.3:a:exim:exim:4.90.0.27
  • Exim » Exim » Version: 4.90.1
    cpe:2.3:a:exim:exim:4.90.1
  • Exim » Exim » Version: 4.91
    cpe:2.3:a:exim:exim:4.91
  • Canonical » Ubuntu Linux » Version: 18.04
    cpe:2.3:o:canonical:ubuntu_linux:18.04
  • Canonical » Ubuntu Linux » Version: 18.10
    cpe:2.3:o:canonical:ubuntu_linux:18.10
  • Debian » Debian Linux » Version: 9.0
    cpe:2.3:o:debian:debian_linux:9.0


Contact Us

Shodan ® - All rights reserved