PT-2021-3130 · Exim 4+6 · Exim 4+6

Published

2018-03-12

·

Updated

2024-06-15

·

CVE-2020-28018

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Exim 4 versions prior to 4.94.2
Description The issue is related to a Use After Free condition in the smtp reset function under certain situations, particularly for builds that include OpenSSL. This could potentially allow an attacker to elevate privileges within the system and execute arbitrary code by sending a specially crafted request. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations For Exim 4 versions prior to 4.94.2, update to version 4.94.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the smtp reset function in situations where OpenSSL is utilized, until a patch is applied.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1409
ALT-PU-2020-2318
ALT-PU-2021-1764
ALT-PU-2022-2269
BDU:2021-02766
CVE-2020-28018
OPENSUSE-SU-2021:0677-1
OPENSUSE-SU-2021:0753-1
OPENSUSE-SU-2021:0754-1
OPENSUSE-SU-2021_0677-1
OPENSUSE-SU-2024:10746-1
USN-4934-1

Affected Products

Alt Linux
Astra Linux
Exim 4
Linuxmint
Openssl
Suse
Ubuntu