9.3
CVSSv2

CVE-2020-28026

Published: 06/05/2021 Updated: 12/07/2022
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 829
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Exim 4 prior to 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Notification (DSN). Certain uses of ORCPT= can place a newline into a spool header file, and indirectly allow unauthenticated remote malicious users to execute arbitrary commands as root.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

exim exim

Vendor Advisories

The Qualys Research Labs reported several vulnerabilities in Exim, a mail transport agent, which could result in local privilege escalation and remote code execution Details can be found in the Qualys advisory at wwwqualyscom/2021/05/04/21nails/21nailstxt For the stable distribution (buster), these problems have been fixed in version 4 ...
Exim 4 before 4942 allows Execution with Unnecessary Privileges Because Exim operates as root in the log directory (owned by a non-root user), a symlink or hard link attack allows overwriting critical root-owned files anywhere on the filesystem (CVE-2020-28007) Exim 4 before 4942 allows Execution with Unnecessary Privileges Because Exim oper ...
A security issue has been found in Exim before version 4942 that allows for line truncation and injection in spool_read_header() ...

Github Repositories

NMAP vulnerability scanning scripts A collection of nmap vulnerability scanning scripts to aid afforable detection and remediation Background These scripts use the Nmap Scripting Engine (NSE) to implement checks for various vulnerabilities References: nmaporg/book/man-nsehtml nmaporg/nsedoc/indexhtml Scripts Exim mailserver CVE-2020-28017 through CVE-20

NMAP Vulnerability Scanning Scripts

NMAP vulnerability scanning scripts A collection of nmap vulnerability scanning scripts to aid afforable detection and remediation Background These scripts use the Nmap Scripting Engine (NSE) to implement checks for various vulnerabilities References: nmaporg/book/man-nsehtml nmaporg/nsedoc/indexhtml Scripts Exim mailserver CVE-2020-28017 through CVE-20