vulnerability
FreeBSD: VID-3e0da406-aece-11e9-8d41-97657151f8c2 (CVE-2019-13917): Exim -- RCE in ${sort} expansion
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 10 | (AV:N/AC:L/Au:N/C:C/I:C/A:C) | Jul 25, 2019 | Jul 27, 2019 | Dec 10, 2025 |
Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Jul 25, 2019
Added
Jul 27, 2019
Modified
Dec 10, 2025
Description
Exim team report: A local or remote attacker can execute programs with root privileges - if you've an unusual configuration. If your configuration uses the ${sort } expansion for items that can be controlled by an attacker (e.g. $local_part, $domain). The default config, as shipped by the Exim developers, does not contain ${sort }. The vulnerability is exploitable either remotely or locally and could be used to execute other programs with root privilege. The ${sort } expansion re-evaluates its items. Exim 4.92.1 is not vulnerable.
Solution
freebsd-upgrade-package-exim
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.