First published: Mon May 11 2020(Updated: )
Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exim Exim | <=4.93 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.10 | |
Canonical Ubuntu Linux | =20.04 | |
ubuntu/exim4 | <4.90.1-1ubuntu1.5 | 4.90.1-1ubuntu1.5 |
ubuntu/exim4 | <4.92.1-1ubuntu3.1 | 4.92.1-1ubuntu3.1 |
ubuntu/exim4 | <4.93-13ubuntu1.1 | 4.93-13ubuntu1.1 |
ubuntu/exim4 | <4.82-3ubuntu2.4+ | 4.82-3ubuntu2.4+ |
ubuntu/exim4 | <4.93-16 | 4.93-16 |
ubuntu/exim4 | <4.86.2-2ubuntu2.6 | 4.86.2-2ubuntu2.6 |
debian/exim4 | 4.94.2-7+deb11u2 4.94.2-7+deb11u3 4.96-15+deb12u4 4.96-15+deb12u5 4.98-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12783 is a vulnerability in Exim version 4.93 and earlier that allows for an out-of-bounds read in the SPA authenticator, potentially leading to authentication bypass.
The severity of CVE-2020-12783 is high with a CVSS score of 7.5.
Exim versions up to and including 4.93 are affected by CVE-2020-12783.
To fix CVE-2020-12783 on Ubuntu, you can update the 'exim4' package to version 4.93-16 or later.
You can find more information about CVE-2020-12783 on the MITRE CVE database, Ubuntu security notices, and NVD.