CVE-2020-8793

OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c.
Configurations

Configuration 1

cpe:2.3:a:opensmtpd:opensmtpd:*:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*

Information

Published : 2020-02-25 05:15

Updated : 2022-01-01 07:30


NVD link : CVE-2020-8793

Mitre link : CVE-2020-8793

Products Affected
No products.
CWE
CWE-367

CWE-426

Untrusted Search Path