This article provides information on Exim vulnerability CVE-2019-15846 and how it impacts Sophos products
Applies to the following Sophos product(s) and version(s) PureMessage for UnixSophos Central EmailSophos Email ApplianceCyberoamSophos UTM Software AppliancePureMessage for Microsoft ExchangeReflexion
CVE-2019-15846 outlines a vulnerability in Exim whereby a specially crafted SNI ending can be utilized to run arbitrary code on the vulnerable server
This vulnerability is not exploitable on any Sophos products, see the table below for more information.
* Despite this vulnerability not being exploitable due to the current architecture of the Sophos XG and Sophos UTM products, we do still plan on releasing a patch for Exim on these platforms in an upcoming Maintenance Release.
Sign up to the Sophos Support SMS Notification Service to get the latest product release information and critical issues.
If you've spotted an error or would like to provide feedback on this article, please use the section below to rate and comment on the article. This is invaluable to us to ensure that we continually strive to give our customers the best information possible.
Every comment submitted here is read (by a human) but we do not reply to specific technical questions. For technical support post a question to the community. Or click here for new feature/product improvements. Alternatively for paid/licensed products open a support ticket.