CVE-2020-12783

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.

References

https://git.exim.org/exim.git/commit/57aa14b216432be381b6295c312065b2fd034f86

https://git.exim.org/exim.git/commit/a04174dc2a84ae1008c23b6a7109e7fa3fb7b8b0

https://bugs.exim.org/show_bug.cgi?id=2571

https://www.debian.org/security/2020/dsa-4687

https://lists.debian.org/debian-lts-announce/2020/05/msg00017.html

https://usn.ubuntu.com/4366-1/

https://lists.fedoraproject.org/archives/list/[email protected]/message/M7Z5UG6ZIG32V7M4PP3BCC65C27EWK7G/

https://lists.fedoraproject.org/archives/list/[email protected]/message/F6IQQ2SERFUD4WMRSX6XYDNK7Q4GPT7Y/

http://www.openwall.com/lists/oss-security/2021/05/04/7

Details

Source: MITRE

Published: 2020-05-11

Updated: 2021-05-04

Type: CWE-125

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Impact Score: 3.6

Exploitability Score: 3.9

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:* versions up to 4.93 (inclusive)

Tenable Plugins

View all (6 total)

IDNameProductFamilySeverity
149614openSUSE Security Update : exim (openSUSE-2021-677) (Stack Clash)NessusSuSE Local Security Checks
critical
138053Amazon Linux AMI : exim (ALAS-2020-1380)NessusAmazon Linux Local Security Checks
high
136842Fedora 31 : exim (2020-93d7305d71)NessusFedora Local Security Checks
high
136731Ubuntu 16.04 LTS / 18.04 LTS / 19.10 / 20.04 : Exim vulnerability (USN-4366-1)NessusUbuntu Local Security Checks
high
136702Debian DLA-2213-1 : exim4 security updateNessusDebian Local Security Checks
high
136676Debian DSA-4687-1 : exim4 - security updateNessusDebian Local Security Checks
high