9

CVE-2019-19920

sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sa-exim Project ≫ Sa-exim Version 4.2.1
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.16% 0.863
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://bugs.debian.org/946829#24
Patch
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2020/01/msg00006.html
Third Party Advisory
Mailing List
https://marc.info/?l=spamassassin-users&m=157668107325768&w=2
Third Party Advisory
Mailing List
https://marc.info/?l=spamassassin-users&m=157668305026635&w=2
Third Party Advisory
Mailing List
https://usn.ubuntu.com/4520-1/
Third Party Advisory