⚠ Actively exploited
Added to CISA KEV on 2022-03-03. Federal agencies required to patch by 2022-03-17. Required action: Apply updates per vendor instructions..
CVE-2019-16928 — Classic Buffer Overflow in Exim
Severity
9.8CRITICALNVD
EPSS
90.0%
top 0.42%
CISA KEV
KEV
Added 2022-03-03
Due 2022-03-17
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedSep 27
KEV addedMar 3
KEV dueMar 17
Latest updateMay 24
CISA Required Action: Apply updates per vendor instructions.
Description
Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages1 packages
Also affects: Debian Linux 10.0, Fedora 29, 30, 31, Ubuntu Linux 19.04
Patches
🔴Vulnerability Details
4🔍Detection Rules
1📋Vendor Advisories
4🕵️Threat Intelligence
13💬Community
3Bugzilla▶
CVE-2019-16928 exim: remotely triggerable buffer overflow in string_vformat() [fedora-all]↗2019-09-30
Bugzilla
▶