cbcvebase.
CVE-2019-19920
published 2019-12-22

CVE-2019-19920: sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than…

PriorityP352high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.16%
86.5th percentile
sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.

Affected

10 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debiansa-exim< sa-exim 4.2.1-19 (bookworm)sa-exim 4.2.1-19 (bookworm)
sa-eximsa-exim>= 0 < 4.2.1-194.2.1-19
sa-eximsa-exim>= 0 < 4.2.1-194.2.1-19
sa-eximsa-exim>= 0 < 4.2.1-194.2.1-19
sa-eximsa-exim>= 0 < 4.2.1-14+deb8u1build0.16.04.14.2.1-14+deb8u1build0.16.04.1
sa-exim_projectsa-exim

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian6.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.