CVE-2020-8794: Critical severity OpenSMTPD OpenSMTPD vulnerability
Last updated 28 April 2026
Other sources
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mtaio in mtasession.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/opensmtpdto a version that resolves this vulnerability.Fixed in 6.8.0p2-3Fixed in 6.8.0p2-4Fixed in 7.6.0p1-1Fixed in 7.8.0p0-2 - Upgrade
Upgrade
OpenSMTPDto a version that resolves this vulnerability.Fixed in 6.6.4 - Compensating control
Mitigate risk by preventing exploitation during bounce handling until OpenSMTPD is upgraded (e.g., limit or isolate systems accepting email/bounce traffic if possible).
Event History
Frequently Asked Questions
What is CVE-2020-8794?
CVE-2020-8794 is a vulnerability that allows remote code execution in OpenSMTPD before version 6.6.4.
How severe is CVE-2020-8794?
CVE-2020-8794 has a severity rating of 9.8, which is considered critical.
Which software versions are affected by CVE-2020-8794?
OpenSMTPD versions before 6.6.4 are affected by CVE-2020-8794.
How can I fix CVE-2020-8794?
To fix CVE-2020-8794, you need to update OpenSMTPD to version 6.6.4 or later.
Where can I find more information about CVE-2020-8794?
You can find more information about CVE-2020-8794 on the MITRE CVE website and the Ubuntu security notices.