Emergency release of the mail server in which a critical vulnerability (CVE-2019-13917) has been fixed, allowing for remote code execution with root privileges under certain specific configuration settings.
The vulnerability Starting from version 4.85 when using the operator "${sort }" in the settings, if the elements used in the "sort" list can be passed by attackers (for example, through variables $local_part and $domain). By default, this operator is not applied in the configuration offered in the standard Exim package and in the package for Debian and Ubuntu (probably in other distributions as well). To check your system for vulnerability, you can run the command "exim -bP config | grep sort".
Package updates addressing the vulnerability have already been released for and . Updates are not yet available for , , and . RHEL and CentOS regarding the issue , as Exim is not included in their standard package repository (if necessary, it is installed from the repository ).
Source: opennet.ru
