Back to search
CVE-2019-16928
Published: Sep 27, 2019
Modified: Oct 21, 2025
PUBLISHED
Description
Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugs.exim.org/show_bug.cgi?id=2449
x_refsource_MISC
[oss-security] 20190928 Exim CVE-2019-16928 RCE using a heap-based buffer overflow
mailing-list
x_refsource_MLIST
[oss-security] 20190928 Re: Exim CVE-2019-16928 RCE using a heap-based buffer overflow
mailing-list
x_refsource_MLIST
[oss-security] 20190928 Re: Exim CVE-2019-16928 RCE using a heap-based buffer overflow
mailing-list
x_refsource_MLIST
DSA-4536
vendor-advisory
x_refsource_DEBIAN
USN-4141-1
vendor-advisory
x_refsource_UBUNTU
[oss-security] 20190929 Re: Exim CVE-2019-16928 RCE using a heap-based buffer overflow
mailing-list
x_refsource_MLIST
20190929 [SECURITY] [DSA 4536-1] exim4 security update
mailing-list
x_refsource_BUGTRAQ
FEDORA-2019-006dfc94cd
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-e080507ba5
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-d778bd4137
vendor-advisory
x_refsource_FEDORA
GLSA-202003-47
vendor-advisory
x_refsource_GENTOO
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now