Mailing List Archive

CVE-2019-13917
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

General release information
===========================

The code fix for this issue has been placed in the project
public git repository; the project website will be updated
in due course.


CVE ID: CVE-2019-13917
OVE ID: OVE-20190718-0006
Date: 2019-07-18
Credits: Jeremy Harris
Version(s): 4.85 up to and including 4.92
Issue: A local or remote attacker can execute programs with root
privileges - if you've an unusual configuration. For details
see below.

Coordinated Release Date (CRD) for Exim 4.92.1:
Thu Jul 25 10:00:00 UTC 2019

Contact: security@exim.org

Details:
A vulnerability was discovered in the "sort" expansion operator:
The elements of the list were expanded, giving a possible attack
if the list included data supplied by an attacker.

If the effective configuration file for exim does not use sort
then the system is trivially declarable as not being vulnerable.
Use this command to check: "exim -bP config | grep sort".

- --
Cheers,
Jeremy
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEqYbzpr1jd9hzCVjevOWMjOQfMt8FAl05cJMACgkQvOWMjOQf
Mt+wyAf9GtHba4nfUCmz/juxXwJjfN2R5OF7S1QcA9gRD/2G8F4rf08VBHkdgAaV
qLjnHR8RcQzMrVmjTLpZA1zZKy21+LCeQUgAKZksGa8/6AVx3k7JGc/vnqT8QMiE
173RTAp9IHh6Y3piYtIbzV3PFlnnRcaRaDSqNJ/c6NWpOzP2IW5mMewMz0n0/cO0
Wm02HadUJ+5fKpnjDIicimPi5Jt7V/ECCVr7ecui2IaY4cnAMoglP439cFAM+4BP
XighCFfqTg7tLikuSshEQiA/D3rYoXBDpBknfXpmK3eQDX6SUf3XiXPG6OB3X/7o
xTjPoxn2MueFxjSvpIlJEeFde535HQ==
=lGYE
-----END PGP SIGNATURE-----

--
## List details at https://lists.exim.org/mailman/listinfo/exim-announce Exim details at http://www.exim.org/ ##