CISA Known Exploited Vulnerability

CVE-2019-10149

Exim · Mail Transfer Agent (MTA)

Exim Mail Transfer Agent (MTA) Improper Input Validation

Date added
BOD 22-01 due date
CWE CWE-78
Ransomware Unknown

CISA description

Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

Required action

Apply updates per vendor instructions.