PT-2020-6036 · Exim+5 · Exim+5

Published

2020-10-20

·

Updated

2024-06-15

·

CVE-2020-28014

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Exim versions prior to 4.94.2
Description The issue is related to errors in privilege management. It allows an attacker to potentially elevate privileges in the system by exploiting the vulnerability, which can lead to a denial of service because root-owned files can be overwritten. The -oP option, available to the exim user, is a key factor in this issue.
Recommendations For versions prior to 4.94.2, update to version 4.94.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the -oP option to prevent potential exploitation.

Exploit

Fix

DoS

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1764
ALT-PU-2022-2269
BDU:2021-02752
CVE-2020-28014
DLA-2650-1
DSA-4912-1
OPENSUSE-SU-2021:0677-1
OPENSUSE-SU-2021:0753-1
OPENSUSE-SU-2021:0754-1
OPENSUSE-SU-2021_0677-1
OPENSUSE-SU-2024:10746-1
USN-4934-1
USN-4934-2

Affected Products

Alt Linux
Astra Linux
Exim
Linuxmint
Suse
Ubuntu