CVE-2020-28014: Medium severity sa-exim vulnerability
Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. The -oP option is available to the exim user, and allows a denial of service because root-owned files can be overwritten.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-28014?
CVE-2020-28014 is a vulnerability in Exim version 4 before 4.94.2 that allows execution with unnecessary privileges.
How does CVE-2020-28014 impact the Exim software?
CVE-2020-28014 allows the exim user to overwrite root-owned files, leading to a denial of service.
What is the severity of CVE-2020-28014?
The severity of CVE-2020-28014 is medium.
How can I fix CVE-2020-28014?
To fix CVE-2020-28014, update your Exim software to version 4.94.2 or later.
Where can I find more information about CVE-2020-28014?
You can find more information about CVE-2020-28014 at the following URL: [https://www.exim.org/static/doc/security/CVE-2020-qualys/CVE-2020-28014-PIDFP.txt](https://www.exim.org/static/doc/security/CVE-2020-qualys/CVE-2020-28014-PIDFP.txt).