CRITICAL KEV
exim: remotely triggerable buffer overflow in string_vformat()
Published Sep 27, 2019 ·Due Mar 17, 2022
9.8
CRITICALCVSS 3.1
EPSS 41.64%
Description
Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.
Affected products
No data.
Configuration 2
- 19.04
Configuration 3
- 10.0
Configuration 4
OR
- 29
- 30
- 31
No data.
Red Hat Enterprise Linux 5
exim
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | exim | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect Red Hat Enterprise Linux 5 as the exim package did not contain the vulnerable code in any of our supported products.
Weaknesses (2)
References (22)
- http://www.openwall.com/lists/oss-security/2019/09/28/1 mailing-listx_refsource_MLISTExploitMailing ListMitigationThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/09/28/2 mailing-listx_refsource_MLISTExploitMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/09/28/3 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/09/28/4 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-16928 Vendor Advisory
- https://bugs.exim.org/show_bug.cgi?id=2449 x_refsource_MISCIssue TrackingPatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1756930 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-7422 Advisory
- https://exim.org/static/doc/security/CVE-2019-16928.txt
- https://git.exim.org/exim.git/commit/478effbfd9c3cc5a627fc671d4bf94d13670d65f x_refsource_MISCPatch
- https://lists.exim.org/lurker/message/20190927.032457.c1044d4c.en.html x_refsource_MISCVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EED7HM3MFIBAP5OIMJAFJ35JAJABTVSC/ vendor-advisoryx_refsource_FEDORARelease Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T3TJW4HPYH3O5HZCWGD6NSHTEBTTAPDC/ vendor-advisoryx_refsource_FEDORARelease Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UY6HPRW7MR3KBQ5JFHH6OXM7YCZBJCOB/ vendor-advisoryx_refsource_FEDORARelease Notes
- https://nvd.nist.gov/vuln/detail/CVE-2019-16928
- https://seclists.org/bugtraq/2019/Sep/60 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202003-47 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://usn.ubuntu.com/4141-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-16928 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2019-16928
- https://www.debian.org/security/2019/dsa-4536 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 27, 2019
Updated Oct 21, 2025
Reserved Sep 27, 2019
Link CVE-2019-16928
CISA Vulnrichment
Updated Feb 4, 2025
ENISA EUVD
EUVD-2019-7422 Assigner mitre
Published Sep 27, 2019
Updated Oct 21, 2025
Exploited since Mar 3, 2022
Link EUVD-2019-7422