CVE-2020-28017

high
Published — · Modified —
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk
8.0

Description

Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients. NOTE: remote exploitation may be difficult because of resource consumption.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2020-28017 NameCVE-2020-28017 DescriptionExim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients. NOTE: remote exploitation may be difficult because of resource consumption. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub…

CVE-2020-28017

NameCVE-2020-28017
DescriptionExim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients. NOTE: remote exploitation may be difficult because of resource consumption.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-2650-1, DSA-4912-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
exim4 (PTS)bullseye4.94.2-7+deb11u3fixed
bullseye (security)4.94.2-7+deb11u5fixed
bookworm4.96-15+deb12u9fixed
bookworm (security)4.96-15+deb12u10fixed
trixie4.98.2-1+deb13u2fixed
trixie (security)4.98.2-1+deb13u3fixed
forky, sid4.99.3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
exim4sourcestretch4.89-2+deb9u8DLA-2650-1
exim4sourcebuster4.92-8+deb10u6DSA-4912-1
exim4source(unstable)4.94.2-1

Notes

https://www.openwall.com/lists/oss-security/2021/05/04/7

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
https://www.openwall.com/lists/oss-security/2021/05/04/7

OS impact

arch Arch Fixed 1 release
VersionStatusFixed in
Fixed 4.94.2-1
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 4.94.2-1
sid Fixed 4.94.2-1
forky Fixed 4.94.2-1
bullseye Fixed 4.94.2-1
bookworm Fixed 4.94.2-1

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.