Description
Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Notification (DSN). Certain uses of ORCPT= can place a newline into a spool header file, and indirectly allow unauthenticated remote attackers to execute arbitrary commands as root.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2650-1 | exim4 security update |
Debian DSA |
DSA-4912-1 | exim4 security update |
EUVD |
EUVD-2020-20517 | Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Notification (DSN). Certain uses of ORCPT= can place a newline into a spool header file, and indirectly allow unauthenticated remote attackers to execute arbitrary commands as root. |
Ubuntu USN |
USN-4934-1 | Exim vulnerabilities |
Ubuntu USN |
USN-4934-2 | Exim vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T16:25:43.970Z
Reserved: 2020-10-30T00:00:00.000Z
Link: CVE-2020-28026
No data.
Status : Modified
Published: 2021-05-06T13:15:09.777
Modified: 2024-11-21T05:22:14.077
Link: CVE-2020-28026
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN