CVE-2020-28018: Use After Free
Published May 6, 2021
·Updated
Exim 4 before 4.94.2 allows Use After Free in smtpreset in certain situations that may be common for builds with OpenSSL.
Affected Software
1 affected component
Exim Exim>=4.90<4.94.2
Event History
May 6, 2021
CVE Published
via MITRE·03:58 AM
Data Sourced
via MITRE·03:58 AM
Description
Frequently Asked Questions
1
What is CVE-2020-28018?
CVE-2020-28018 is a vulnerability in Exim 4 before 4.94.2 that allows Use After Free in smtp_reset in certain situations.
2
What is the severity of CVE-2020-28018?
CVE-2020-28018 has a severity rating of critical with a score of 9.8.
3
How does CVE-2020-28018 affect Exim?
CVE-2020-28018 affects Exim versions between 4.90 and 4.94.2.
4
How can I fix CVE-2020-28018?
To fix CVE-2020-28018, update Exim to version 4.94.2 or later.
5
What is CWE-416?
CWE-416 refers to Use After Free vulnerabilities, which is the type of vulnerability present in CVE-2020-28018.