Permissions, Privileges, and Access Controls in OpenSMTPD - CVE-2020-8793
Published: February 25, 2020 / Updated: September 23, 2021
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the application does not drop privileges when executing the "/usr/sbin/smtpctl" application with a "-bi" command-line argument. A local user can leverage this behavior and use a specially crafted hardlink to execute arbitrary code on the system with elevated privileges.
Affected software
opensmtpd (Ubuntu package)
libasr
opensmtpd
Fedora
How to mitigate CVE-2020-8793
opensmtpd (Ubuntu package) - addressed in versions 6.0.3p1-1ubuntu0.2, 6.0.3p1-6ubuntu0.2
libasr - update to 1.0.4-2.el7
opensmtpd - addressed in versions 6.6.4p1-1.el8, 6.6.4p1-1.fc30, 6.6.4p1-1.fc31, 6.6.4p1-2.fc32, 6.6.4p1-3.el7
Links to Public Exploits and PoC-codes
- Exploit #6785 - OpenSMTPD (A mass exploitation tool for CVE 2020-8793 ) (September 23, 2021)
- Exploit #5761 - OpenSMTPD 6.6.3 - Arbitrary File Read (June 17, 2021)
- Exploit #5205 - OpenSMTPD (A mass exploitation tool for CVE 2020-8793 ) (March 12, 2021)
- Exploit #4891 - OpenSMTPD (A mass exploitation tool for CVE 2020-8793 ) (November 30, 2020)