Back

CRITICAL KEV

exim: remotely triggerable buffer overflow in string_vformat()

Published Sep 27, 2019 ·Due Mar 17, 2022

Description

Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.

Affected products

Remediation

Red Hat statement

This issue did not affect Red Hat Enterprise Linux 5 as the exim package did not contain the vulnerable code in any of our supported products.

References (22)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 27, 2019
Updated Oct 21, 2025
Reserved Sep 27, 2019
CISA Vulnrichment
Updated Feb 4, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Sep 27, 2019
ENISA EUVD
Assigner mitre
Published Sep 27, 2019
Updated Oct 21, 2025
Exploited since Mar 3, 2022
EUVD-2019-7422