Lucene search

K
cvelistMitreCVELIST:CVE-2020-28024
HistoryMay 06, 2021 - 4:31 a.m.

CVE-2020-28024

2021-05-0604:31:25
mitre
www.cve.org
3
exim vulnerability
buffer underwrite
remote code execution
cve-2020-28024
smtp_ungetc
arbitrary commands

AI Score

9.5

Confidence

High

EPSS

0.005

Percentile

76.7%

Exim 4 before 4.94.2 allows Buffer Underwrite that may result in unauthenticated remote attackers executing arbitrary commands, because smtp_ungetc was only intended to push back characters, but can actually push back non-character error codes such as EOF.