FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Exim -- RCE in ${sort} expansion

Affected packages
4.85 <= exim < 4.92.1

Details

VuXML ID 3e0da406-aece-11e9-8d41-97657151f8c2
Discovery 2019-07-18
Entry 2019-07-25
Modified 2019-07-26

Exim team report:

A local or remote attacker can execute programs with root privileges - if you've an unusual configuration.

If your configuration uses the ${sort } expansion for items that can be controlled by an attacker (e.g. $local_part, $domain). The default config, as shipped by the Exim developers, does not contain ${sort }.

The vulnerability is exploitable either remotely or locally and could be used to execute other programs with root privilege. The ${sort } expansion re-evaluates its items.

Exim 4.92.1 is not vulnerable.

References

CVE Name CVE-2019-13917
URL https://www.exim.org/static/doc/security/CVE-2019-13917.txt