CVE-2019-10149

CRITICAL9.8⚠ KEVEPSS 93.9%

exim4 - security update

Published: 6/5/2019Modified: 4/28/2026Added to CISA KEV: 1/10/2022

Description

A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (1)