Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-8794

Опубликовано: 25 фев. 2020
Источник: debian
EPSS Высокий

Описание

OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opensmtpdfixed6.6.4p1-1package

Примечания

  • https://www.openwall.com/lists/oss-security/2020/02/24/5

  • https://poolp.org/posts/2020-01-30/opensmtpd-advisory-dissected/

  • https://www.openwall.com/lists/oss-security/2020/02/26/1

EPSS

Процентиль: 99%
0.88136
Высокий

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 6 лет назад

OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling.

CVSS3: 9.8
nvd
почти 6 лет назад

OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling.

CVSS3: 9.8
github
больше 3 лет назад

OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling.

CVSS3: 9.8
fstec
почти 6 лет назад

Уязвимость реализации функции mta_io (mta_session.c) почтового демона OpenSMTPD, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 99%
0.88136
Высокий