Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2019-10149

Published: 4 June 2019

A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

Priority

Medium

CVSS 3 base score: 9.8

Status

Package Release Status
exim4
Launchpad, Ubuntu, Debian
bionic
Released (4.90.1-1ubuntu1.2)
cosmic
Released (4.91-6ubuntu1.1)
disco Not vulnerable
(4.92-4ubuntu1)
precise Does not exist

trusty Not vulnerable
(4.82-3ubuntu2.4)
upstream Needs triage

xenial Not vulnerable
(4.86.2-2ubuntu2.3)