Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2019-19920
Description:sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.
Test IDs: 1.3.6.1.4.1.25623.1.0.892062   1.3.6.1.4.1.25623.1.0.844594  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2019-19920
https://bugs.debian.org/946829#24
https://marc.info/?l=spamassassin-users&m=157668107325768&w=2
https://marc.info/?l=spamassassin-users&m=157668305026635&w=2
https://lists.debian.org/debian-lts-announce/2020/01/msg00006.html
https://usn.ubuntu.com/4520-1/




© 1998-2025 E-Soft Inc. All rights reserved.