Junglewise Threat Intelligence

CVE-2019-16928: Exim Out-of-bounds Write Vulnerability

CVE-2019-16928 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-03

Technologies: Exim. Vendors: Exim.

Executive brief

Exim contains a heap-based buffer overflow in the string_vformat function in string.c. The vulnerability is triggered by a long EHLO command, allowing for remote code execution.

Affected products

  • Exim Exim 4.92 through 4.92.2

Timeline

  • 2019-09-27: advisory: Vendor advisory published via mailing list
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-03: disclosed: NVD publication date

Related threats