⚠ Actively exploited
Added to CISA KEV on 2022-03-03. Federal agencies required to patch by 2022-03-17. Required action: Apply updates per vendor instructions..

CVE-2019-16928Classic Buffer Overflow in Exim

Severity
9.8CRITICALNVD
EPSS
90.0%
top 0.42%
CISA KEV
KEV
Added 2022-03-03
Due 2022-03-17
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedSep 27
KEV addedMar 3
KEV dueMar 17
Latest updateMay 24
CISA Required Action: Apply updates per vendor instructions.

Description

Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDexim/exim4.924.92.2

Also affects: Debian Linux 10.0, Fedora 29, 30, 31, Ubuntu Linux 19.04

Patches

🔴Vulnerability Details

4
GHSA
GHSA-xg2f-gj2p-r7xq: Exim 42022-05-24
OSV
CVE-2019-16928: Exim 42019-09-27
CVEList
CVE-2019-16928: Exim 42019-09-27
VulnCheck
Exim Out-of-bounds Write Vulnerability2019

🔍Detection Rules

1
Suricata
ET EXPLOIT Possible EXIM DoS (CVE-2019-16928)2019-09-30

📋Vendor Advisories

4
CISA
Exim Out-of-bounds Write Vulnerability2022-03-03
Ubuntu
Exim vulnerability2019-09-28
Red Hat
exim: remotely triggerable buffer overflow in string_vformat()2019-09-27
Debian
CVE-2019-16928: exim4 - Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability...2019

🕵️Threat Intelligence

13
Tenable
How COVID-19 Response Is Expanding the Cyberattack Surface2020-03-30
Trendmicro
Partnership Advances DevSecOps, Cybersecurity Issues2019-10-11
Trendmicro
Partnership Advances DevSecOps, Cybersecurity Issues2019-10-11
Trendmicro
CVE-2019-16928: Exim Vuln Exploit via EHLO Strings2019-10-10
Trendmicro
CVE-2019-16928: Exim Vuln Exploit via EHLO Strings2019-10-10

💬Community

3
Bugzilla
CVE-2019-16928 exim: remotely triggerable buffer overflow in string_vformat() [fedora-all]2019-09-30
Bugzilla
CVE-2019-16928 exim: remotely triggerable buffer overflow in string_vformat() [epel-all]2019-09-30
Bugzilla
CVE-2019-16928 exim: remotely triggerable buffer overflow in string_vformat()2019-09-30