7.5
CVSSv3

CVE-2020-35679

Published: 24/12/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

smtpd/table.c in OpenSMTPD prior to 6.8.0p1 lacks a certain regfree, which might allow malicious users to trigger a "very significant" memory leak via messages to an instance that performs many regex lookups.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opensmtpd opensmtpd 6.8.0

opensmtpd opensmtpd

fedoraproject fedora 32

fedoraproject fedora 33

Vendor Advisories

Debian Bug report logs - #978038 opensmtpd: CVE-2020-35679 Package: src:opensmtpd; Maintainer for src:opensmtpd is Ryan Kavanagh <rak@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 24 Dec 2020 22:18:02 UTC Severity: important Tags: security, upstream Found in version opensmtpd/680p1~ ...
smtpd/tablec in OpenSMTPD before 680p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak via messages to an instance that performs many regex lookups ...