SMTP: Exim deliver_message Command Injection Remote Code Execution
This signature detects attempts to exploit a known vulnerability against Exim. Successful exploitation results in the execution of arbitrary commands as the root user.
Extended Description
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
Affected Products
Debian debian_linux
References
BugTraq: 108679
CVE: CVE-2019-10149
URL: https://exim.org/static/doc/security/cve-2019-10149.txt https://www.openwall.com/lists/oss-security/2019/06/06/1
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Debian
Exim
Canonical
10.0