CVE-2020-8794
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling.
- Opensmtpd
- < 6.6.4
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 88.9% (100th percentile)
- Weakness
- CWE-125
- NVD status
- Modified
- Published
- 2020-02-25
CVE-2020-8794 at NVD
9 known exploits for CVE-2020-8794
Proof-of-concept code and exploit modules indexed by Sploitus
π Qualys Security Advisory - Exim 21Nails Advisory
OpenSMTPD - OOB Read Local Privilege Escalation (Metasploit)
OpenSMTPD Out-Of-Bounds Read / Local Privilege Escalation Exploit
OpenSMTPD Out-Of-Bounds Read / Local Privilege Escalation
OpenSMTPD < 6.6.3p1 - Local Privilege Escalation / Remote Code Execution Exploit
OpenSMTPD 6.6.3p1 - Local Privilege Escalation + Remote Code Execution
OpenSMTPD < 6.6.3p1 - Local Privilege Escalation + Remote Code Execution
OpenSMTPD Out-Of-Bounds Read
OpenSMTPD OOB Read Local Privilege Escalation