Back

CRITICAL

exim: out-of-bounds access in string_interpret_escape() leading to buffer overflow in the SMTP delivery process

Published Sep 6, 2019

Description

Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.

Affected products

Remediation

Red Hat statement

The flaw in the string_interpret_escape() function exists in the versions of Exim as shipped with Red Hat Enterprise Linux 5. However, it is not exposed to untrusted inputs and therefore it can not be exploited to achieve remote code execution. Refer to Red Hat Bugzilla bug 1748397 for further technical details: https://bugzilla.redhat.com/show_bug.cgi?id=1748397#c6 Exim mail server is not shipped with Red Hat Enterprise Linux 6, 7, and 8.

References (28)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Sep 6, 2019
Updated Aug 5, 2024
Reserved Sep 2, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Critical
Public date Sep 6, 2019
Bugzilla 1748397

ENISA EUVD

Assigner mitre
Published Sep 6, 2019
Updated Aug 5, 2024

GitHub

No data