Related Vulnerabilities: CVE-2020-7247  

A vulnerability was discovered in OpenSMTPd before version 6.6.2 which allows arbiterary code execution by constructing a mail FROM address that escapes the regex filter.

Severity Critical

Remote Yes

Type Arbitrary code execution

Description

A vulnerability was discovered in OpenSMTPd before version 6.6.2 which allows arbiterary code execution by constructing a mail FROM address that escapes the regex filter.

AVG-1090 opensmtpd 6.6.1p1-1 6.6.2p1-1 Critical Fixed

https://www.openwall.com/lists/oss-security/2020/01/28/3
https://github.com/OpenSMTPD/OpenSMTPD/commit/d2688c097e0ff53037c7403e09426771876a3907