CVE-2020-28016: High severity sa-exim vulnerability
Published May 6, 2021
·Updated
Exim 4 before 4.94.2 allows an off-by-two Out-of-bounds Write because "-F ''" is mishandled by parsefixphrase.
Affected Software
1 affected component
Exim Exim>=4.00<4.94.2
Event History
May 6, 2021
CVE Published
via MITRE·03:51 AM
Data Sourced
via MITRE·03:51 AM
Description
Frequently Asked Questions
1
What is CVE-2020-28016?
CVE-2020-28016 is a vulnerability in Exim 4 before version 4.94.2 that allows an off-by-two out-of-bounds write.
2
How severe is CVE-2020-28016?
CVE-2020-28016 has a severity score of 7.8 (high) based on the CVSS v3.0 rating system.
3
Which software versions are affected by CVE-2020-28016?
CVE-2020-28016 affects Exim 4 versions from 4.00 to 4.94.1.
4
How is CVE-2020-28016 exploited?
CVE-2020-28016 is exploited by mishandling the "-F ''" option in Exim, leading to an off-by-two out-of-bounds write.
5
Is there a fix available for CVE-2020-28016?
Yes, the fix for CVE-2020-28016 is included in Exim version 4.94.2, so upgrading to this version or later will resolve the vulnerability.