Critical vulnerability in Exim allowing remote code execution with root privileges

Exim Mail Server Developers have notified users about a critical vulnerability (CVE-2019-15846), allowing a local or remote attacker to execute their code on the server with root privileges. No publicly available exploits for this issue have been documented yet, but researchers who identified the vulnerability have prepared a preliminary exploit prototype.

A coordinated release of package updates and a corrective release is scheduled for September 6 (1:00 PM MSK) Exim 4.92.2. Until then, detailed information about the issue is not subject to disclosure. All Exim users need to prepare for an emergency unscheduled update.

This year marks the third critical vulnerability in Exim. According to the September automated survey of over two million mail servers, Exim holds a share of 57.13% (up from 56.99% a year ago), Postfix is used on 34.7% (up from 34.11%) of mail servers, Sendmail – 3.94% (down from 4.24%), and Microsoft Exchange – 0.53% (down from 0.68%).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster