Researchers have discovered a critical vulnerability in the Exim email server software. The vulnerability could allow attackers to remotely compromise victims' systems and execute malicious code on the servers.
The Exim email server maintainers have released an urgent security update, Exim version 4.92.3. All versions from 4.92 to 4.92.2 are vulnerable.
Exim is a very popular open-source mail transfer agent (MTA). It is designed for Unix-like operating systems, such as Linux, Mac OSX or Solaris. This means that it runs on almost 60% of email servers.
Exim administrators issued another urgent security update earlier this month to fix a critical vulnerability (CVE-2019-15846), which also allowed remote code execution, allowing hackers to gain administrator privileges on a victim's system.
The new vulnerability, codenamed CVE-2019-16928 , was discovered by Jeremy Harris of the Exim. It is a heap-based buffer overflow.

Attackers could exploit the vulnerability to remotely perform a denial of service attack or execute malicious code on the Exim mail server.
A few months ago, Exim was found to have another vulnerability (CVE-2019-10149), which was used by hackers to launch attacks on vulnerable servers. Exim administrators took care to fix the bug as soon as they discovered its existence.
As it turns out, Exim mail is quite vulnerable to security flaws, which hackers are eager to exploit. Users and server administrators should install the latest version of Exim, 4.92.3, as soon as possibleto address the security and avoid putting their system at risk.
Administrators released the security update for Linux, including Ubuntu, Arch Linux, Fedora, FreeBSD, and Debian.
