Vulnerability Details CVE-2020-28026
Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Notification (DSN). Certain uses of ORCPT= can place a newline into a spool header file, and indirectly allow unauthenticated remote attackers to execute arbitrary commands as root.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 78.4%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 9.3
Products affected by CVE-2020-28026
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:exim:exim:4.80.1
-
-
cpe:2.3:a:exim:exim:4.82.1
-
cpe:2.3:a:exim:exim:4.84.2
-
-
cpe:2.3:a:exim:exim:4.85.1
-
cpe:2.3:a:exim:exim:4.85.2
-
-
cpe:2.3:a:exim:exim:4.86.1
-
cpe:2.3:a:exim:exim:4.86.2
-
-
cpe:2.3:a:exim:exim:4.87.1
-
-
-
cpe:2.3:a:exim:exim:4.89.1
-
-
cpe:2.3:a:exim:exim:4.90.0.22
-
cpe:2.3:a:exim:exim:4.90.0.27
-
cpe:2.3:a:exim:exim:4.90.1
-
-
-
cpe:2.3:a:exim:exim:4.92.1
-
cpe:2.3:a:exim:exim:4.92.2
-
-
cpe:2.3:a:exim:exim:4.93.0.4
-
cpe:2.3:a:exim:exim:4.93.0.4-3.1
-
-
cpe:2.3:a:exim:exim:4.94.1