PT-2020-20283 · Openbsd+1 · Opensmtpd+1
Published
2020-02-25
·
Updated
2022-01-01
·
CVE-2020-8793
CVSS v3.1
4.7
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenSMTPD versions prior to 6.6.4
Description
The issue allows local users to read arbitrary files due to a combination of an untrusted search path in
makemap.c and race conditions in the offline functionality in smtpd.c. This can be particularly problematic on some Linux distributions.Recommendations
For versions prior to 6.6.4, update to version 6.6.4 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files that could be read through this vulnerability until the update is applied.
Exploit
Fix
Time Of Check To Time Of Use
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opensmtpd
Ubuntu