Back

CVE-2019-16928

CRITICAL CISA KEV

Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.

Published: Sep 27, 2019 Modified: Jun 17, 2026
CWE-787 CWE-787

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (6)

Vendor Product Version
exim exim * ≥ 4.92
canonical ubuntu_linux 19.04
debian debian_linux 10.0
fedoraproject fedora 29
fedoraproject fedora 30
fedoraproject fedora 31

GitHub Security Advisory GHSA-xg2f-gj2p-r7xq

Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 42.48%

Top 1% most likely to be exploited

Threat Score 81.9 / 100

CISA Known Exploited

Date Added: 2022-03-03
Due Date: 2022-03-17
Required Action:

Apply updates per vendor instructions.

Data Sources

NVD CISA KEV EPSS GitHub