Exim 4 before 4.94.2 allows Heap-based Buffer Overflow because it mishandles "-F '.('" on the command line, and thus may allow privilege escalation from any user to root. This occurs because of the interpretation of negative sizes in strncpy.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2650-1 exim4 security update
Debian DSA Debian DSA DSA-4912-1 exim4 security update
EUVD EUVD EUVD-2020-20504 Exim 4 before 4.94.2 allows Heap-based Buffer Overflow because it mishandles "-F '.('" on the command line, and thus may allow privilege escalation from any user to root. This occurs because of the interpretation of negative sizes in strncpy.
Ubuntu USN Ubuntu USN USN-4934-1 Exim vulnerabilities
Ubuntu USN Ubuntu USN USN-4934-2 Exim vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T16:25:43.971Z

Reserved: 2020-10-30T00:00:00

Link: CVE-2020-28013

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-05-06T13:15:09.430

Modified: 2024-11-21T05:22:12.123

Link: CVE-2020-28013

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.