CVE-2020-28013

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
06/05/2021
Last modified:
10/05/2021

Description

Exim 4 before 4.94.2 allows Heap-based Buffer Overflow because it mishandles "-F '.('" on the command line, and thus may allow privilege escalation from any user to root. This occurs because of the interpretation of negative sizes in strncpy.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:* 4.00 (including) 4.94.2 (excluding)