CVE-2020-28008: High severity sa-exim vulnerability
Published May 6, 2021
·Updated
Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the spool directory (owned by a non-root user), an attacker can write to a /var/spool/exim4/input spool header file, in which a crafted recipient address can indirectly lead to command execution.
Affected Software
1 affected component
Exim Exim>=4.00<4.94.2
Event History
May 6, 2021
CVE Published
via MITRE·03:07 AM
Data Sourced
via MITRE·03:07 AM
Description
Frequently Asked Questions
1
What is CVE-2020-28008?
CVE-2020-28008 is a vulnerability in Exim 4 before 4.94.2 that allows execution with unnecessary privileges.
2
What is the severity of CVE-2020-28008?
CVE-2020-28008 has a severity value of 7.8, which is considered high.
3
How does CVE-2020-28008 work?
CVE-2020-28008 allows an attacker to write to a spool header file in the /var/spool/exim4/input directory, which can lead to command execution.
4
Which software is affected by CVE-2020-28008?
Exim versions before 4.94.2 are affected by CVE-2020-28008.
5
How can CVE-2020-28008 be fixed?
To fix CVE-2020-28008, you should update Exim to version 4.94.2 or later.