CVE-2020-12783: High severity sa-exim vulnerability
Published May 11, 2020
·Updated
Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.
Affected Software
18 affected componentsFixes available
ubuntu/exim4<4.90.1-1ubuntu1.5
4.90.1-1ubuntu1.5
ubuntu/exim4<4.92.1-1ubuntu3.1
4.92.1-1ubuntu3.1
ubuntu/exim4<4.93-13ubuntu1.1
4.93-13ubuntu1.1
ubuntu/exim4<4.82-3ubuntu2.4+
4.82-3ubuntu2.4+
ubuntu/exim4<4.93-16
4.93-16
ubuntu/exim4<4.86.2-2ubuntu2.6
4.86.2-2ubuntu2.6
debian/exim4
4.94.2-7+deb11u24.94.2-7+deb11u34.96-15+deb12u44.96-15+deb12u54.98-1
Exim Exim<=4.93
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.10
Canonical Ubuntu Linux=20.04
Remediation
Event History
May 11, 2020
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·01:51 PM
Data Sourced
via MITRE·01:51 PM
Description
Aug 4, 2024
Data Sourced
via Launchpad·12:13 PM
Description
Frequently Asked Questions
1
What is CVE-2020-12783?
CVE-2020-12783 is a vulnerability in Exim version 4.93 and earlier that allows for an out-of-bounds read in the SPA authenticator, potentially leading to authentication bypass.
2
What is the severity of CVE-2020-12783?
The severity of CVE-2020-12783 is high with a CVSS score of 7.5.
3
Which software versions are affected by CVE-2020-12783?
Exim versions up to and including 4.93 are affected by CVE-2020-12783.
4
How can I fix CVE-2020-12783 on Ubuntu?
To fix CVE-2020-12783 on Ubuntu, you can update the 'exim4' package to version 4.93-16 or later.
5
Where can I find more information about CVE-2020-12783?
You can find more information about CVE-2020-12783 on the MITRE CVE database, Ubuntu security notices, and NVD.