USN-4294-1: OpenSMTPD vulnerabilities
It was discovered that OpenSMTPD mishandled certain input. A remote, unauthenticated attacker could use this vulnerability to execute arbitrary shell commands as any non-root user. (CVE-2020-8794) It was discovered that OpenSMTPD did not properly handle hardlinks under certain conditions. An unprivileged local attacker could read the first line of any file on the filesystem. (CVE-2020-8793)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the OpenSMTPD vulnerabilities?
The vulnerability ID for the OpenSMTPD vulnerabilities is CVE-2020-8794.
What is the severity of CVE-2020-8794?
The severity of CVE-2020-8794 is high.
How can an attacker exploit CVE-2020-8794?
An attacker can exploit CVE-2020-8794 by sending specially crafted input to OpenSMTPD, allowing them to execute arbitrary shell commands as a non-root user.
Which versions of OpenSMTPD are affected by CVE-2020-8794?
Versions up to and including 6.0.3p1-6ubuntu0.2 for Ubuntu 19.10 and up to and including 6.0.3p1-1ubuntu0.2 for Ubuntu 18.04 are affected by CVE-2020-8794.
How do I fix the OpenSMTPD vulnerabilities?
To fix the OpenSMTPD vulnerabilities, update to version 6.0.3p1-6ubuntu0.2 for Ubuntu 19.10 or version 6.0.3p1-1ubuntu0.2 for Ubuntu 18.04.