CVE-2020-28015: High severity sa-exim vulnerability
Published May 6, 2021
·Updated
Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters. Local users can alter the behavior of root processes because a recipient address can have a newline character.
Affected Software
1 affected component
Exim Exim>=4.00<4.94.2
Event History
May 6, 2021
CVE Published
via MITRE·03:46 AM
Data Sourced
via MITRE·03:46 AM
Description
Frequently Asked Questions
1
What is CVE-2020-28015?
CVE-2020-28015 is a vulnerability in Exim 4 where local users can alter the behavior of root processes due to improper neutralization of line delimiters.
2
How severe is CVE-2020-28015?
The severity of CVE-2020-28015 is high, with a CVSS score of 7.8.
3
Which software versions are affected by CVE-2020-28015?
Exim versions between 4.00 and 4.94.2 are affected by CVE-2020-28015.
4
How can local users exploit CVE-2020-28015?
Local users can exploit CVE-2020-28015 by altering the behavior of root processes using a recipient address with a newline character.
5
Is there a fix for CVE-2020-28015?
Yes, upgrading to Exim version 4.94.2 or above fixes the CVE-2020-28015 vulnerability.