PT-2020-6041 · Exim+5 · Exim+5

Published

2020-10-20

·

Updated

2024-06-15

·

CVE-2020-28009

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Exim versions prior to 4.94.2
Description The issue is related to an integer overflow to buffer overflow in the get stdinput() function, allowing unbounded reads accompanied by unbounded increases in a certain size variable. This could potentially allow an attacker to elevate privileges or execute arbitrary code. However, exploitation may be impractical due to the execution time needed to overflow, which could take multiple days.
Recommendations For Exim versions prior to 4.94.2, update to version 4.94.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the get stdinput() function until a patch is available.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1764
ALT-PU-2022-2269
BDU:2021-02759
CVE-2020-28009
DLA-2650-1
DSA-4912-1
OPENSUSE-SU-2021:0677-1
OPENSUSE-SU-2021:0753-1
OPENSUSE-SU-2021:0754-1
OPENSUSE-SU-2021_0677-1
OPENSUSE-SU-2024:10746-1
USN-4934-1
USN-4934-2

Affected Products

Alt Linux
Astra Linux
Exim
Linuxmint
Suse
Ubuntu