CISA KEV 정보
| 취약점명 | Exim Out-of-bounds Write Vulnerability |
|---|---|
| 설명 | Exim contains an out-of-bounds write vulnerability which can allow for remote code execution. |
| 조치사항 | Apply updates per vendor instructions. |
| 랜섬웨어 캠페인 악용 | Unknown |
| CWE | CWE-787 |
| 등록일 (KEV) | 2022-03-03 |
| 조치 기한 | 2022-03-17 |
| 추가 참고 | https://nvd.nist.gov/vuln/detail/CVE-2019-16928 |
NVD 상세 정보
CVSS v3.1: 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS v2.0: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P설명: Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.
CWE: CWE-787 | CWE-787
참조
- http://www.openwall.com/lists/oss-security/2019/09/28/1 [Exploit, Mailing List, Mitigation, Third Party Advisory]
- http://www.openwall.com/lists/oss-security/2019/09/28/2 [Exploit, Mailing List, Third Party Advisory]
- http://www.openwall.com/lists/oss-security/2019/09/28/3 [Mailing List, Third Party Advisory]
- http://www.openwall.com/lists/oss-security/2019/09/28/4 [Mailing List, Third Party Advisory]
- https://bugs.exim.org/show_bug.cgi?id=2449 [Issue Tracking, Patch, Vendor Advisory]
- https://git.exim.org/exim.git/commit/478effbfd9c3cc5a627fc671d4bf94d13670d65f [Patch]
- https://lists.exim.org/lurker/message/20190927.032457.c1044d4c.en.html [Vendor Advisory]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EED7HM3MFIBAP5OIMJAFJ35JAJABTVSC/ [Release Notes]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T3TJW4HPYH3O5HZCWGD6NSHTEBTTAPDC/ [Release Notes]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UY6HPRW7MR3KBQ5JFHH6OXM7YCZBJCOB/ [Release Notes]
- https://seclists.org/bugtraq/2019/Sep/60 [Mailing List, Third Party Advisory]
- https://security.gentoo.org/glsa/202003-47 [Third Party Advisory]
- https://usn.ubuntu.com/4141-1/ [Third Party Advisory]
- https://www.debian.org/security/2019/dsa-4536 [Third Party Advisory]
- http://www.openwall.com/lists/oss-security/2019/09/28/1 [Exploit, Mailing List, Mitigation, Third Party Advisory]
- ... 외 14건
This product uses the NVD API but is not endorsed or certified by the NVD.