exim: Remote command execution in deliver_message() function in /src/deliver.c
Published Jun 5, 2019 ·Due Jul 10, 2022
9.8
CRITICALCVSS 3.1
EPSS 99.96%
Description
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
Affected products
-
- Version 4.92StatusaffectedConstraints-
- Version
Configuration 2
- 18.04
- 18.10
- 9.0
No data.
Red Hat Enterprise Linux 5
exim
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | exim | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Exim is vulnerable since version 4.87, therefore the version of exim package (exim-4.63) shipped with Red Hat Enterprise Linux 5 is not affected by this flaw.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:C/I:C/A:C
Date Added
Jan 10, 2022
Patch Due
Jul 10, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 7, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (25 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 99.96% (0.99961) | 99.98th | v5 (v2026.06.15) |
| Jun 15, 2026 | 99.96% (0.99961) | 99.98th | v5 (v2026.06.15) |
| Mar 17, 2025 | 93.93% (0.93927) | 99.87th | v4 (v2025.03.14) |
| Dec 12, 2024 | 97.41% (0.97414) | 99.95th | v3 (v2023.03.01) |
| May 29, 2024 | 97.37% (0.97368) | 99.90th | v3 (v2023.03.01) |
| Apr 10, 2024 | 97.36% (0.97358) | 99.89th | v3 (v2023.03.01) |
| Mar 25, 2024 | 97.34% (0.97344) | 99.89th | v3 (v2023.03.01) |
| Mar 5, 2024 | 97.39% (0.97390) | 99.91th | v3 (v2023.03.01) |
| Jan 31, 2024 | 97.37% (0.97373) | 99.89th | v3 (v2023.03.01) |
| Jan 19, 2024 | 97.25% (0.97252) | 99.82th | v3 (v2023.03.01) |
| Dec 17, 2023 | 97.22% (0.97219) | 99.79th | v3 (v2023.03.01) |
| Dec 2, 2023 | 97.14% (0.97142) | 99.75th | v3 (v2023.03.01) |
| Nov 16, 2023 | 97.35% (0.97349) | 99.87th | v3 (v2023.03.01) |
| Nov 1, 2023 | 97.43% (0.97430) | 99.92th | v3 (v2023.03.01) |
| Aug 15, 2023 | 97.44% (0.97436) | 99.91th | v3 (v2023.03.01) |
| Jul 8, 2023 | 97.45% (0.97445) | 99.91th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.51% (0.97511) | 99.96th | v3 (v2023.03.01) |
| Mar 6, 2023 | 94.95% (0.94954) | 99.96th | v2 (v2022.01.01) |
| Feb 4, 2022 | 94.95% (0.94954) | 99.96th | v2 (v2022.01.01) |
| Feb 3, 2022 | 76.63% (0.76635) | 99.79th | v1 |
| Sep 16, 2021 | 76.63% (0.76635) | 99.89th | v1 |
| Sep 14, 2021 | 30.74% (0.30742) | 98.65th | v1 |
| Sep 1, 2021 | 76.63% (0.76635) | 99.89th | v1 |
| May 5, 2021 | 76.63% (0.76635) | 0.00th | v1 |
| Apr 14, 2021 | 75.74% (0.75744) | 0.00th | v1 |
References (26)
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00020.html vendor-advisoryMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/153218/Exim-4.9.1-Remote-Command-Execution.html ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/153312/Exim-4.91-Local-Privilege-Escalation.html ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/154198/Exim-4.91-Local-Privilege-Escalation.html ExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2019/Jun/16 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/06/05/2 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/06/05/3 mailing-listMailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/06/05/4 mailing-listExploitMailing List
- http://www.openwall.com/lists/oss-security/2019/06/06/1 mailing-listExploitMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/07/25/6 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/07/25/7 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/07/26/4 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/05/04/7 mailing-listMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/108679 vdb-entryBroken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2019-10149 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1715237 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10149 Issue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10149
- https://seclists.org/bugtraq/2019/Jun/5 mailing-listMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/201906-01 vendor-advisoryThird Party Advisory
- https://usn.ubuntu.com/4010-1/ vendor-advisoryThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-10149 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2019-10149
- https://www.debian.org/security/2019/dsa-4456 vendor-advisoryThird Party Advisory
- https://www.exim.org/static/doc/security/CVE-2019-10149.txt Vendor Advisory
Change history (0)
No recorded changes yet.