ISOMAN

CVE

CVE-2020-8793

OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c.

Severity
MEDIUM
CVSS
4.7
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
Ubuntu18.04.6 amd64 desktopunknownsource
Ubuntu18.04.6 amd64 live-serverunknownsource

References

  1. http://seclists.org/fulldisclosure/2020/Feb/28
  2. http://www.openwall.com/lists/oss-security/2020/02/24/4
  3. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OPH4QU4DNVHA7ACFXMYFCEP5PSXXPN4E/
  4. https://usn.ubuntu.com/4294-1/
  5. https://www.openbsd.org/security.html
  6. http://seclists.org/fulldisclosure/2020/Feb/28
  7. http://www.openwall.com/lists/oss-security/2020/02/24/4
  8. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OPH4QU4DNVHA7ACFXMYFCEP5PSXXPN4E/
  9. https://usn.ubuntu.com/4294-1/
  10. https://www.openbsd.org/security.html