CVE-2020-7247: OpenSMTPD Remote Code Execution Vulnerability
Last updated 25 August 2025
Other sources
smtpmailaddr in smtpsession.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM field. This affects the "uncommented" default configuration. The issue exists because of an incorrect return value upon failure of input validation.
— Launchpad
smtpmailaddr in smtpsession.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/opensmtpdto a version that resolves this vulnerability.Fixed in 6.8.0p2-3Fixed in 6.8.0p2-4Fixed in 7.6.0p1-1Fixed in 7.8.0p0-2
Event History
Frequently Asked Questions
What is CVE-2020-7247?
CVE-2020-7247 is a remote code execution vulnerability in OpenSMTPD.
How does CVE-2020-7247 work?
CVE-2020-7247 allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, using shell metacharacters in a MAIL FROM field.
What is the severity of CVE-2020-7247?
CVE-2020-7247 has a severity rating of 9.8 (Critical).
Which software products are affected by CVE-2020-7247?
OpenSMTPD 6.6 in OpenBSD 6.6 and other products are affected by CVE-2020-7247.
How can I fix CVE-2020-7247?
To fix CVE-2020-7247, you should update to the patched version of OpenSMTPD provided by your vendor or distribution.