Heap-based buffer overflow in Exim - CVE-2019-16928
Published: September 28, 2019 / Updated: March 8, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the string_vformat() function in string.c when processing an overly long argument for EHLO command. A remote non-authenticated attacker can send a very long string as an argument for the EHLO command, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
Amazon Linux AMI
Arch Linux
Fedora
exim4 (Debian package)
exim (Alpine package)
exim4 (Ubuntu package)
fedpkg
exim
How to mitigate CVE-2019-16928
exim4 (Debian package) - update to 4.92-8+deb10u3
exim (Alpine package) - addressed in versions 4.92.2-r1, 4.92.3-r0
exim4 (Ubuntu package) - update to 4.92-4ubuntu1.4
fedpkg - addressed in versions 1.37-8.el6, 1.37-8.fc29
exim - addressed in versions 4.92.3-1.el6, 4.92.3-1.el7, 4.92.3-1.fc29, 4.92.3-1.fc30, 4.92.3-1.fc31
External References
- http://www.openwall.com/lists/oss-security/2019/09/28/1
- http://www.openwall.com/lists/oss-security/2019/09/28/2
- http://www.openwall.com/lists/oss-security/2019/09/28/3
- https://bugs.exim.org/show_bug.cgi?id=2449
- https://git.exim.org/exim.git/commit/478effbfd9c3cc5a627fc671d4bf94d13670d65f
- https://lists.exim.org/lurker/message/20190927.032457.c1044d4c.en.html
Related Security Bulletins
- Remote code execution in Exim
- Debian update for exim4
- Ubuntu update for Exim
- Arch Linux update for exim
- Amazon Linux AMI update for exim
- Gentoo update for Exim
- Heap-based buffer overflow in exim (Alpine package)
- Fedora 31 update for exim
- Fedora 30 update for exim
- Fedora 29 update for exim
- Fedora EPEL 7 update for exim
- Fedora EPEL 6 update for exim
- Fedora 29 update for fedpkg
- Fedora EPEL 6 update for fedpkg