PT-2020-6044 · Exim+5 · Exim+5

Published

2020-10-20

·

Updated

2024-06-15

·

CVE-2020-28021

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Exim versions 4 through 4.94.1 Exim version 4.94.2 is not affected, so all versions prior to 4.94.2 are considered vulnerable.
Description The issue is related to insufficient input validation in the Exim message relay agent. This can be exploited by a remote attacker to bypass security restrictions. An authenticated remote SMTP client can insert newline characters into a spool file, which can indirectly lead to remote code execution as root via the AUTH= parameter in a MAIL FROM command. The MAIL FROM command is an API endpoint used in SMTP transactions.
Recommendations For Exim versions 4 through 4.94.1, update to version 4.94.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the AUTH= parameter in the MAIL FROM command to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1764
ALT-PU-2022-2269
BDU:2021-02762
CVE-2020-28021
DLA-2650-1
DSA-4912-1
OPENSUSE-SU-2021:0677-1
OPENSUSE-SU-2021:0753-1
OPENSUSE-SU-2021:0754-1
OPENSUSE-SU-2021_0677-1
OPENSUSE-SU-2024:10746-1
USN-4934-1

Affected Products

Alt Linux
Astra Linux
Exim
Linuxmint
Suse
Ubuntu