First published: Thu May 06 2021(Updated: )
Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences. This occurs because use of certain getc functions is mishandled when a client uses BDAT instead of DATA.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exim Exim | >=4.88<4.94.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2020-28019.
The severity of CVE-2020-28019 is high with a CVSS score of 7.5.
Exim 4 versions before 4.94.2 are affected by CVE-2020-28019.
CVE-2020-28019 can lead to recursion-based stack consumption or other consequences.
To mitigate CVE-2020-28019, you should update to Exim version 4.94.2 or later.