コンテンツに移動
Informational

Informational

Exim CVE-2019-15846 and Sophos Products

CVE(N)

CVE-2019-15846

PRODUCT(S)

Sophos Email

Sophos Firewall

Sophos UTM

更新日

2019 Oct 16

記事バージョン

1

公開日

2019 Oct 16

公開 ID

sophos-sa-20191016-exim-cve

回避策

No

Overview

CVE-2019-15846 outlines a vulnerability in Exim whereby a specially crafted SNI ending can be utilized to run arbitrary code on the vulnerable server

This vulnerability is not exploitable on any Sophos products, see the table below for more information.

Sophos Email Products and CVE-2019-15846

ProductVulnerableFurther information
Sophos XG FirewallNoThe TLS headers that are used to exploit this vulnerability are stripped by the product before reaching the vulnerable Exim code. *
Sophos UTMNoThe TLS headers that are used to exploit this vulnerability are stripped by the product before reaching the vulnerable Exim code. *
Sophos Email on CentralNoProduct doesn't utilize Exim
Sophos Email ApplianceNoProduct doesn't utilize Exim
Puremessage for UnixNoProduct doesn't utilize Exim
Puremessage for ExchangeNoProduct doesn't utilize Exim
CyberoamNoProduct doesn't utilize Exim
ReflexionNo Product doesn't utilize Exim 

 

* Despite this vulnerability not being exploitable due to the current architecture of the Sophos XG and Sophos UTM products, we do still plan on releasing a patch for Exim on these platforms in an upcoming Maintenance Release. 

Related information

http://exim.org/static/doc/security/CVE-2019-15846.txt

Sophos Logo

Sophos Responsible Disclosure Policy

To learn about Sophos security vulnerability disclosure policies and publications, see the Responsible Disclosure Policy.