Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-13917

Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $local_part or $domain).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.189
EPSS Ranking 95.0%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Products affected by CVE-2019-13917
  • Exim » Exim » Version: 4.85
    cpe:2.3:a:exim:exim:4.85
  • Exim » Exim » Version: 4.85.1
    cpe:2.3:a:exim:exim:4.85.1
  • Exim » Exim » Version: 4.85.2
    cpe:2.3:a:exim:exim:4.85.2
  • Exim » Exim » Version: 4.86
    cpe:2.3:a:exim:exim:4.86
  • Exim » Exim » Version: 4.86.1
    cpe:2.3:a:exim:exim:4.86.1
  • Exim » Exim » Version: 4.86.2
    cpe:2.3:a:exim:exim:4.86.2
  • Exim » Exim » Version: 4.87
    cpe:2.3:a:exim:exim:4.87
  • Exim » Exim » Version: 4.87.1
    cpe:2.3:a:exim:exim:4.87.1
  • Exim » Exim » Version: 4.88
    cpe:2.3:a:exim:exim:4.88
  • Exim » Exim » Version: 4.89
    cpe:2.3:a:exim:exim:4.89
  • Exim » Exim » Version: 4.89.1
    cpe:2.3:a:exim:exim:4.89.1
  • Exim » Exim » Version: 4.90
    cpe:2.3:a:exim:exim:4.90
  • Exim » Exim » Version: 4.90.0.22
    cpe:2.3:a:exim:exim:4.90.0.22
  • Exim » Exim » Version: 4.90.0.27
    cpe:2.3:a:exim:exim:4.90.0.27
  • Exim » Exim » Version: 4.90.1
    cpe:2.3:a:exim:exim:4.90.1
  • Exim » Exim » Version: 4.91
    cpe:2.3:a:exim:exim:4.91
  • Exim » Exim » Version: 4.92
    cpe:2.3:a:exim:exim:4.92
  • Debian » Debian Linux » Version: 10.0
    cpe:2.3:o:debian:debian_linux:10.0
  • Debian » Debian Linux » Version: 9.0
    cpe:2.3:o:debian:debian_linux:9.0


Contact Us

Shodan ® - All rights reserved