CVE Vulnerabilities

CVE-2020-28026

Published: May 06, 2021 | Modified: Jul 12, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Notification (DSN). Certain uses of ORCPT= can place a newline into a spool header file, and indirectly allow unauthenticated remote attackers to execute arbitrary commands as root.

Affected Software

Name Vendor Start Version End Version
Exim Exim 4.00 (including) 4.94.2 (excluding)
Exim4 Ubuntu bionic *
Exim4 Ubuntu devel *
Exim4 Ubuntu esm-infra/xenial *
Exim4 Ubuntu focal *
Exim4 Ubuntu groovy *
Exim4 Ubuntu hirsute *
Exim4 Ubuntu impish *
Exim4 Ubuntu jammy *
Exim4 Ubuntu trusty *
Exim4 Ubuntu trusty/esm *
Exim4 Ubuntu xenial *

References