Improper Neutralization of Line Delimiters in Exim Mail Transfer Agent
CVE-2020-28021
8.8HIGH
What is CVE-2020-28021?
Exim Mail Transfer Agent versions prior to 4.94.2 exhibit a flaw due to improper neutralization of line delimiters. This vulnerability allows an authenticated remote SMTP client to manipulate spool files by injecting newline characters through the AUTH= command in a MAIL FROM context. Exploitation of this issue can lead to the potential execution of arbitrary commands with root privileges, posing a significant security threat to systems using affected versions.