CVE-2020-28024: Critical severity sa-exim vulnerability
Exim 4 before 4.94.2 allows Buffer Underwrite that may result in unauthenticated remote attackers executing arbitrary commands, because smtpungetc was only intended to push back characters, but can actually push back non-character error codes such as EOF.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-28024?
CVE-2020-28024 is a vulnerability in Exim 4 before 4.94.2 that allows unauthenticated remote attackers to execute arbitrary commands.
What is the severity of CVE-2020-28024?
The severity of CVE-2020-28024 is critical with a CVSS score of 9.8.
How does CVE-2020-28024 happen?
CVE-2020-28024 occurs due to a buffer underwrite vulnerability in Exim that allows non-character error codes to be pushed back, leading to arbitrary command execution.
Which version of Exim is affected by CVE-2020-28024?
Exim versions before 4.94.2 are affected by CVE-2020-28024.
Is authentication required for exploiting CVE-2020-28024?
No, CVE-2020-28024 can be exploited by unauthenticated remote attackers.