CVE-2019-10149 is a critical remote command execution vulnerability affecting Exim mail server versions 4.87 through 4.91, impacting various Canonical and Debian Linux distributions. This flaw stems from improper validation of recipient addresses within the deliver_message() function. With a CVSS score of 9.8 (CRITICAL), it allows unauthenticated attackers to execute arbitrary commands remotely with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, with public exploit code available in Metasploit and ExploitDB, and has garnered significant community discussion and media coverage due to its widespread impact on millions of mail servers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.87, <= 4.91CPE matchmatch criteria | cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* | ||
18.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
exim: Remote command execution in deliver_message() function in /src/deliver.c
Jun 4, 2019Security Advisory for CVE-2019-10149
Security Advisory for CVE-2019-10149