Heap-based Buffer Overflow in Exim Email Server
CVE-2020-28013

7.8HIGH

Key Information:

Vendor

Exim

Status
Vendor
CVE Published:
6 May 2021

What is CVE-2020-28013?

A vulnerability in Exim Email Server prior to version 4.94.2 allows for a heap-based buffer overflow, triggered by the mishandling of the '-F '.(' command line option. This flaw can potentially enable an attacker to escalate privileges, providing unauthorized access from any user to the root level. The issue arises due to the incorrect interpretation of negative sizes in the strncpy function, highlighting a significant security risk for systems running vulnerable versions of Exim.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.