Vulnerability Details CVE-2020-28013
Exim 4 before 4.94.2 allows Heap-based Buffer Overflow because it mishandles "-F '.('" on the command line, and thus may allow privilege escalation from any user to root. This occurs because of the interpretation of negative sizes in strncpy.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.6%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 7.2
Products affected by CVE-2020-28013
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:exim:exim:4.80.1
-
-
cpe:2.3:a:exim:exim:4.82.1
-
cpe:2.3:a:exim:exim:4.84.2
-
-
cpe:2.3:a:exim:exim:4.85.1
-
cpe:2.3:a:exim:exim:4.85.2
-
-
cpe:2.3:a:exim:exim:4.86.1
-
cpe:2.3:a:exim:exim:4.86.2
-
-
cpe:2.3:a:exim:exim:4.87.1
-
-
-
cpe:2.3:a:exim:exim:4.89.1
-
-
cpe:2.3:a:exim:exim:4.90.0.22
-
cpe:2.3:a:exim:exim:4.90.0.27
-
cpe:2.3:a:exim:exim:4.90.1
-
-
-
cpe:2.3:a:exim:exim:4.92.1
-
cpe:2.3:a:exim:exim:4.92.2
-
-
cpe:2.3:a:exim:exim:4.93.0.4
-
cpe:2.3:a:exim:exim:4.93.0.4-3.1
-
-
cpe:2.3:a:exim:exim:4.94.1