CVE-2019-19920
published 2019-12-22CVE-2019-19920: sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than…
PriorityP352high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.16%
86.5th percentile
sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | sa-exim | < sa-exim 4.2.1-19 (bookworm) | sa-exim 4.2.1-19 (bookworm) |
| sa-exim | sa-exim | >= 0 < 4.2.1-19 | 4.2.1-19 |
| sa-exim | sa-exim | >= 0 < 4.2.1-19 | 4.2.1-19 |
| sa-exim | sa-exim | >= 0 < 4.2.1-19 | 4.2.1-19 |
| sa-exim | sa-exim | >= 0 < 4.2.1-14+deb8u1build0.16.04.1 | 4.2.1-14+deb8u1build0.16.04.1 |
| sa-exim_project | sa-exim | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-28xw-m7jp-89ch: sa-exim 4
ghsa_unreviewed·2022-05-24·CVSS 6.7
CVE-2019-19920 [MEDIUM] CWE-78 GHSA-28xw-m7jp-89ch: sa-exim 4
sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.
OSV
sa-exim vulnerability
osv·2020-09-18·CVSS 8.8
CVE-2019-19920 [HIGH] sa-exim vulnerability
sa-exim vulnerability
It was discovered that Exim SpamAssassin does not properly handle
configuration strings. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2019-19920)
OSV
CVE-2019-19920: sa-exim 4
osv·2019-12-22·CVSS 6.7
CVE-2019-19920 [MEDIUM] CVE-2019-19920: sa-exim 4
sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.
Ubuntu
Exim SpamAssassin vulnerability
vendor_ubuntu·2020-09-18·CVSS 8.8
CVE-2019-19920 [HIGH] Exim SpamAssassin vulnerability
Title: Exim SpamAssassin vulnerability
Summary: Exim SpamAssassin could be made to execute aribitrary code if it received
crafted .cf files/rules.
It was discovered that Exim SpamAssassin does not properly handle
configuration strings. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2019-19920)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-19920: sa-exim - sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf...
vendor_debian·2019·CVSS 6.7
CVE-2019-19920 [MEDIUM] CVE-2019-19920: sa-exim - sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf...
sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.
Scope: local
bookworm: resolved (fixed in 4.2.1-19)
bullseye: resolved (fixed in 4.2.1-19)
sid: resolved (fixed in 4.2.1-19)
trixie: resolved (fixed in 4.2.1-19)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.debian.org/946829#24https://lists.debian.org/debian-lts-announce/2020/01/msg00006.htmlhttps://marc.info/?l=spamassassin-users&m=157668107325768&w=2https://marc.info/?l=spamassassin-users&m=157668305026635&w=2https://usn.ubuntu.com/4520-1/https://bugs.debian.org/946829#24https://lists.debian.org/debian-lts-announce/2020/01/msg00006.htmlhttps://marc.info/?l=spamassassin-users&m=157668107325768&w=2https://marc.info/?l=spamassassin-users&m=157668305026635&w=2https://usn.ubuntu.com/4520-1/
2019-12-22
Published