CVE-2020-28026: Critical severity sa-exim vulnerability
Published May 6, 2021
·Updated
Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Notification (DSN). Certain uses of ORCPT= can place a newline into a spool header file, and indirectly allow unauthenticated remote attackers to execute arbitrary commands as root.
Affected Software
1 affected component
Exim Exim>=4.00<4.94.2
Event History
May 6, 2021
CVE Published
via MITRE·04:41 AM
Data Sourced
via MITRE·04:41 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Exim vulnerability?
The vulnerability ID for this Exim vulnerability is CVE-2020-28026.
2
What is the severity of CVE-2020-28026?
The severity of CVE-2020-28026 is critical.
3
Which versions of Exim are affected by CVE-2020-28026?
Exim versions from 4.00 to 4.94.2 are affected by CVE-2020-28026.
4
What is the impact of CVE-2020-28026?
CVE-2020-28026 can allow unauthenticated remote attackers to execute arbitrary code.
5
Is there a fix available for CVE-2020-28026?
Yes, the fix for CVE-2020-28026 is included in Exim version 4.94.2.