5
CVSSv2

CVE-2020-12783

Published: 11/05/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Exim up to and including 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

exim exim

fedoraproject fedora 31

fedoraproject fedora 32

debian debian linux 8.0

debian debian linux 9.0

debian debian linux 10.0

canonical ubuntu linux 18.04

canonical ubuntu linux 14.04

canonical ubuntu linux 19.10

canonical ubuntu linux 20.04

canonical ubuntu linux 16.04

Vendor Advisories

Exim could be made to access sensitive information or bypass authentication if it received a specially crafted input ...
It was discovered that exim4, a mail transport agent, suffers from a authentication bypass vulnerability in the spa authentication driver The spa authentication driver is not enabled by default For the oldstable distribution (stretch), this problem has been fixed in version 489-2+deb9u7 For the stable distribution (buster), this problem has bee ...
Exim through 493 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spac and auths/auth-spac (CVE-2020-12783) ...