CVE-2019-13917: Debian Linux

Critical severity, CVSS 9.8. EPSS: 8.6% chance of exploitation in the next 30 days.

Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $local_part or $domain).

Affected products

  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Exim Exim: from 4.85, up to and including 4.92

Published 2019-07-25. Last modified 2026-06-17.