CVE-2020-28011: Buffer Overflow
Exim 4 before 4.94.2 allows Heap-based Buffer Overflow in queuerun via two sender options: -R and -S. This may cause privilege escalation from exim to root.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-28011?
CVE-2020-28011 is a vulnerability in Exim 4 before version 4.94.2 that allows for a heap-based buffer overflow in queue_run through the use of two sender options.
How does CVE-2020-28011 impact my system?
CVE-2020-28011 can lead to privilege escalation from Exim to root, potentially allowing an attacker to gain unauthorized access to sensitive information or execute arbitrary code.
How severe is CVE-2020-28011?
CVE-2020-28011 has a severity rating of 7.8 (high) according to the Common Vulnerability Scoring System (CVSS).
Which versions of Exim are affected by CVE-2020-28011?
Exim versions prior to 4.94.2 are affected by CVE-2020-28011.
How can I fix CVE-2020-28011?
To fix CVE-2020-28011, it is recommended to upgrade to Exim version 4.94.2 or later.