exim.orgConfirmation
http://exim.org/static/doc/security/CVE-2019-13917.txt CVE-2019-13917
CRITICAL
Record summary
CVE-2019-13917 has a selected CVSS score of 9.8 (critical).
Description
Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $local_part or $domain).
Description source: CVE List
References
6[oss-security] 20190726 Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release aheadmailing list
http://www.openwall.com/lists/oss-security/2019/07/26/5 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-13917 20190730 [SECURITY] [DSA 4488-1] exim4 security updatemailing list
https://seclists.org/bugtraq/2019/Jul/51 GLSA-201909-06Vendor advisory
https://security.gentoo.org/glsa/201909-06 DSA-4488Vendor advisory
https://www.debian.org/security/2019/dsa-4488