PT-2020-20283 · Openbsd+1 · Opensmtpd+1

Published

2020-02-25

·

Updated

2022-01-01

·

CVE-2020-8793

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSMTPD versions prior to 6.6.4
Description The issue allows local users to read arbitrary files due to a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c. This can be particularly problematic on some Linux distributions.
Recommendations For versions prior to 6.6.4, update to version 6.6.4 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files that could be read through this vulnerability until the update is applied.

Exploit

Fix

Time Of Check To Time Of Use

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8793
USN-4294-1
USN-4875-1

Affected Products

Opensmtpd
Ubuntu