PT-2020-6044 · Exim+5 · Exim+5
Published
2020-10-20
·
Updated
2024-06-15
·
CVE-2020-28021
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Exim versions 4 through 4.94.1
Exim version 4.94.2 is not affected, so all versions prior to 4.94.2 are considered vulnerable.
Description
The issue is related to insufficient input validation in the Exim message relay agent. This can be exploited by a remote attacker to bypass security restrictions. An authenticated remote SMTP client can insert newline characters into a spool file, which can indirectly lead to remote code execution as root via the
AUTH= parameter in a MAIL FROM command. The MAIL FROM command is an API endpoint used in SMTP transactions.Recommendations
For Exim versions 4 through 4.94.1, update to version 4.94.2 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
AUTH= parameter in the MAIL FROM command to minimize the risk of exploitation.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Exim
Linuxmint
Suse
Ubuntu