vendor:
OpenSMTPD
by:
1F98D
9.8
CVSS
CRITICAL
Remote Code Execution
78
CWE
Product Name: OpenSMTPD
Affected Version From: OpenSMTPD < 6.6.2
Affected Version To: OpenSMTPD < 6.6.2
Patch Exists: YES
Related CWE: CVE-2020-7247
CPE: a:opensmtpd:opensmtpd
Other Scripts:
N/A
Platforms Tested: Debian 9.11 (x64)
2020
OpenSMTPD 6.6.1 – Remote Code Execution
OpenSMTPD after commit a8e222352f and before version 6.6.2 does not adequately escape dangerous characters from user-controlled input. An attacker can exploit this to execute arbitrary shell commands on the target.
Mitigation:
Upgrade to OpenSMTPD 6.6.2 or later