CVE-2019-19920

HIGH WAF: High
CVSS 8.8 Published: 2019-12-22
CWE-78

sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.

WAF Coverage Analysis

OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
sa-exim_projectsa-exim4.2.1
canonicalubuntu_linux16.04
debiandebian_linux8.0
debiandebian_linux9.0
debiandebian_linux10.0

References

Back to CVE Database