6.1
CVSSv3

CVE-2020-28014

Published: 06/05/2021 Updated: 12/07/2022
CVSS v2 Base Score: 5.6 | Impact Score: 7.8 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.1 | Impact Score: 4.2 | Exploitability Score: 1.8
VMScore: 498
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:C

Vulnerability Summary

Exim 4 prior to 4.94.2 allows Execution with Unnecessary Privileges. The -oP option is available to the exim user, and allows a denial of service because root-owned files can be overwritten.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

exim exim

Vendor Advisories

The Qualys Research Labs reported several vulnerabilities in Exim, a mail transport agent, which could result in local privilege escalation and remote code execution Details can be found in the Qualys advisory at wwwqualyscom/2021/05/04/21nails/21nailstxt For the stable distribution (buster), these problems have been fixed in version 4 ...
Exim 4 before 4942 allows Execution with Unnecessary Privileges Because Exim operates as root in the log directory (owned by a non-root user), a symlink or hard link attack allows overwriting critical root-owned files anywhere on the filesystem (CVE-2020-28007) Exim 4 before 4942 allows Execution with Unnecessary Privileges Because Exim oper ...
A security issue has been found in Exim before version 4942 that allows for arbitrary PID file creation ...

Mailing Lists

Dear Exim-Users Abstract -------- Several exploitable vulnerabilities in Exim were reported to us and are fixed We have prepared a security release, tagged as "exim-4942" This release contains all changes on the exim-494+fixes branch plus security fixes You should update your Exim instances as soon as possible (See below for short upgra ...
Qualys Security Advisory 21Nails: Multiple vulnerabilities in Exim ======================================================================== Contents ======================================================================== Summary Local vulnerabilities - CVE-2020-28007: Link attack in Exim's log directory - CVE-2020-28008: Assorted attacks in Ex ...