Integer overflow in Exim - CVE-2020-28020
Published: May 4, 2021 / Updated: May 4, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in receive_msg() function. A remote non-authenticated attacker can send specially crafted data to the mail server, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
Ubuntu
exim4-base (Ubuntu package)
exim4-daemon-heavy (Ubuntu package)
exim4-daemon-light (Ubuntu package)
How to mitigate CVE-2020-28020
exim4-base (Ubuntu package) - addressed in versions 4.86.22ubuntu2.6+esm1, 4.90.1-1ubuntu1.8, 4.93-13ubuntu1.5, 4.94-7ubuntu1.2, 4.94-15ubuntu1.2
exim4-daemon-heavy (Ubuntu package) - addressed in versions 4.86.22ubuntu2.6+esm1, 4.90.1-1ubuntu1.8, 4.93-13ubuntu1.5, 4.94-7ubuntu1.2, 4.94-15ubuntu1.2
exim4-daemon-light (Ubuntu package) - addressed in versions 4.86.22ubuntu2.6+esm1, 4.90.1-1ubuntu1.8, 4.93-13ubuntu1.5, 4.94-7ubuntu1.2, 4.94-15ubuntu1.2