First published: Thu May 06 2021(Updated: )
Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exim Exim | >=4.90<4.94.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28018 is a vulnerability in Exim 4 before 4.94.2 that allows Use After Free in smtp_reset in certain situations.
CVE-2020-28018 has a severity rating of critical with a score of 9.8.
CVE-2020-28018 affects Exim versions between 4.90 and 4.94.2.
To fix CVE-2020-28018, update Exim to version 4.94.2 or later.
CWE-416 refers to Use After Free vulnerabilities, which is the type of vulnerability present in CVE-2020-28018.