VDB
BDU%3A2019-02827
BDU%3A2019-02827
PUBLISHED
CVSS 10 CRITICAL
Уязвимость функции deliver_message() (/src/deliver.c) почтового сервера Exim, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| exim | exim | 4.92 |
| Canonical Ltd., ООО «РусБИТех-Астра», GNU General Public License, Сообщество свободного программного обеспечения, ООО «Ред Софт» | Ubuntu, Astra Linux Special Edition (запись в едином реестре российских программ №369), exim, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition для «Эльбрус» (запись в едином реестре российских программ №11156) |
Timeline
- Jun 10, 2019 PoC Published
- Jun 13, 2019 PoC Published
- Jun 17, 2019 PoC Published
- Aug 8, 2019 CVE Published
- Aug 23, 2019 PoC Published
- Aug 26, 2019 PoC Published
- May 28, 2020 PoC Published
- May 29, 2020 PoC Published
- Jun 16, 2020 PoC Published
- Oct 9, 2020 PoC Published
- Oct 22, 2020 PoC Published
- Oct 22, 2020 PoC Published
References
- https://access.redhat.com/security/cve/cve-2019-10149 url
- https://nvd.nist.gov/vuln/detail/CVE-2019-10149 url
- https://packetstormsecurity.com/files/153218/Exim-4.9.1-Remote-Command-Execution.html url
- https://usn.ubuntu.com/4010-1/ url
- https://www.debian.org/security/2019/dsa-4456 url
- https://www.exim.org/static/doc/security/CVE-2019-10149.txt url
- https://wiki.astralinux.ru/pages/viewpage.action?pageId=44892734 url
- https://wiki.astralinux.ru/pages/viewpage.action?pageId=67111271 url
- https://wiki.astralinux.ru/astra-linux-se81-bulletin-20200429SE81 advisory
- [oss-security] 20190605 Re: CVE-2019-10149: Exim 4.87 to 4.91: possible remote exploit mailing-list
- [oss-security] 20190605 Re: CVE-2019-10149: Exim 4.87 to 4.91: possible remote exploit mailing-list
- [oss-security] 20190605 Re: CVE-2019-10149: Exim 4.87 to 4.91: possible remote exploit mailing-list
- 20190605 [SECURITY] [DSA 4456-1] exim4 security update mailing-list
- GLSA-201906-01 vendor-advisory
- [oss-security] 20190606 Re: CVE-2019-10149: Exim 4.87 to 4.91: possible remote exploit mailing-list
- 108679 vdb
- openSUSE-SU-2019:1524 vendor-advisory
- 20190611 The Return of the WIZard: RCE in Exim (CVE-2019-10149) mailing-list
- [oss-security] 20190725 Re: Statistics for distros lists updated for 2019Q2 mailing-list
- [oss-security] 20190725 Re: Statistics for distros lists updated for 2019Q2 mailing-list
…and 7 more