Back

CRITICAL KEV

exim: Remote command execution in deliver_message() function in /src/deliver.c

Published Jun 5, 2019 ·Due Jul 10, 2022

Description

A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

Affected products

Remediation

Red Hat statement

Exim is vulnerable since version 4.87, therefore the version of exim package (exim-4.63) shipped with Red Hat Enterprise Linux 5 is not affected by this flaw.

Metrics

References (26)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 5, 2019
Updated Oct 21, 2025
Reserved Mar 27, 2019
CISA Vulnrichment
Updated Feb 7, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Jun 4, 2019