CVE-2020-28013: Buffer Overflow
Published May 6, 2021
·Updated
Exim 4 before 4.94.2 allows Heap-based Buffer Overflow because it mishandles "-F '.('" on the command line, and thus may allow privilege escalation from any user to root. This occurs because of the interpretation of negative sizes in strncpy.
Affected Software
1 affected component
Exim Exim>=4.00<4.94.2
Event History
May 6, 2021
CVE Published
via MITRE·03:39 AM
Data Sourced
via MITRE·03:39 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Exim vulnerability?
The vulnerability ID for this Exim vulnerability is CVE-2020-28013.
2
What is the severity of CVE-2020-28013?
The severity of CVE-2020-28013 is high with a CVSS score of 7.8.
3
How does CVE-2020-28013 impact Exim?
CVE-2020-28013 allows for a heap-based buffer overflow in Exim, which may lead to privilege escalation from any user to root.
4
Which versions of Exim are affected by CVE-2020-28013?
Exim versions before 4.94.2 are affected by CVE-2020-28013.
5
How can CVE-2020-28013 be mitigated?
The recommended mitigation for CVE-2020-28013 is to update Exim to version 4.94.2 or later.