Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:26892
HistorySep 21, 2020 - 6:24 a.m.

Remote Code Execution (RCE)

2020-09-2106:24:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.975 High

EPSS

Percentile

100.0%

opensmtpd:bionic is vulnerable to denial of service (DoS). smtp_mailaddr in smtp_session.c allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM field. This affects the “uncommented” default configuration. The issue exists because of an incorrect return value upon failure of input validation.

References