First published: Thu May 06 2021(Updated: )
Exim 4 before 4.94.2 allows an off-by-two Out-of-bounds Write because "-F ''" is mishandled by parse_fix_phrase.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exim Exim | >=4.00<4.94.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28016 is a vulnerability in Exim 4 before version 4.94.2 that allows an off-by-two out-of-bounds write.
CVE-2020-28016 has a severity score of 7.8 (high) based on the CVSS v3.0 rating system.
CVE-2020-28016 affects Exim 4 versions from 4.00 to 4.94.1.
CVE-2020-28016 is exploited by mishandling the "-F ''" option in Exim, leading to an off-by-two out-of-bounds write.
Yes, the fix for CVE-2020-28016 is included in Exim version 4.94.2, so upgrading to this version or later will resolve the vulnerability.