VulnerabilityModified
CVE-2019-19920
sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule.
HIGH 8.8EPSS 3.16%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.16%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.16% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- sa-exim project/sa-exim · canonical/ubuntu linux · debian/debian linux
- Source
- cve@mitre.org
References
- https://bugs.debian.org/946829#24Mailing List, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/01/msg00006.htmlMailing List, Third Party Advisory
- https://marc.info/?l=spamassassin-users&m=157668107325768&w=2Mailing List, Third Party Advisory
- https://marc.info/?l=spamassassin-users&m=157668305026635&w=2Mailing List, Third Party Advisory
- https://usn.ubuntu.com/4520-1/Third Party Advisory
- https://bugs.debian.org/946829#24Mailing List, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/01/msg00006.htmlMailing List, Third Party Advisory
- https://marc.info/?l=spamassassin-users&m=157668107325768&w=2Mailing List, Third Party Advisory
- https://marc.info/?l=spamassassin-users&m=157668305026635&w=2Mailing List, Third Party Advisory
- https://usn.ubuntu.com/4520-1/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.