Back to search
CVE-2020-7247
Published: Jan 29, 2020
Modified: Oct 21, 2025
PUBLISHED
Description
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM field. This affects the "uncommented" default configuration. The issue exists because of an incorrect return value upon failure of input validation.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://www.openbsd.org/security.html
x_refsource_CONFIRM
http://www.openwall.com/lists/oss-security/2020/01/28/3
x_refsource_MISC
20200129 [SECURITY] [DSA 4611-1] opensmtpd security update
mailing-list
x_refsource_BUGTRAQ
DSA-4611
vendor-advisory
x_refsource_DEBIAN
VU#390745
third-party-advisory
x_refsource_CERT-VN
20200131 LPE and RCE in OpenSMTPD (CVE-2020-7247)
mailing-list
x_refsource_FULLDISC
USN-4268-1
vendor-advisory
x_refsource_UBUNTU
FEDORA-2020-b92d7083ca
vendor-advisory
x_refsource_FEDORA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now