VDB

CVE-2020-7247

CVE-2020-7247 PUBLISHED KEV CVSS 9.800000190734863 CRITICAL

smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM field. This affects the "uncommented" default configuration. The issue exists because of an incorrect return value upon failure of input validation.

EPSS 98.97% · 99.9th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
98.97%
99.9th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSopensmtpd5.4.2p1-4, 0, 5.7.3p2-1
Ubuntu:Pro:14.04:LTSopensmtpd5.4.1p1-1, 0, 5.3.3p1-4
Ubuntu:18.04:LTSopensmtpd6.0.3p1-1, 6.0.2p1-2build1, 0

Timeline

  • CVE Published
  • Jan 29, 2020 PoC Published
  • Jan 30, 2020 PoC Published
  • Jan 30, 2020 PoC Published
  • Feb 7, 2020 PoC Published
  • Feb 10, 2020 PoC Published
  • Feb 10, 2020 PoC Published
  • Feb 11, 2020 PoC Published
  • Feb 11, 2020 PoC Published
  • Feb 13, 2021 VulnCheck XDB Entry
  • Feb 17, 2021 PoC Published
  • Apr 7, 2021 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›