CVE-2020-28021: Critical severity sa-exim vulnerability
Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters. An authenticated remote SMTP client can insert newline characters into a spool file (which indirectly leads to remote code execution as root) via AUTH= in a MAIL FROM command.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-28021?
CVE-2020-28021 is a vulnerability in Exim 4 before version 4.94.2 that allows an authenticated remote SMTP client to insert newline characters into a spool file, leading to remote code execution as root.
What is the severity of CVE-2020-28021?
CVE-2020-28021 has a severity score of 8.8 (Critical).
How does CVE-2020-28021 impact Exim?
CVE-2020-28021 allows an authenticated remote SMTP client to manipulate spool files, potentially leading to remote code execution as root.
Which versions of Exim are affected by CVE-2020-28021?
Exim versions up to and including 4.94.2 are affected by CVE-2020-28021.
How can CVE-2020-28021 be mitigated?
To mitigate CVE-2020-28021, users should update to Exim version 4.94.2 or later.