Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 710680 - mail-mta/opensmtpd: arbitrary commands execution in smtp_mailaddr in smtp_session.c via crafted SMTP session (CVE-2020-7247)
Summary: mail-mta/opensmtpd: arbitrary commands execution in smtp_mailaddr in smtp_ses...
Status: RESOLVED DUPLICATE of bug 707828
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~1 [ebuild cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2020-02-24 17:45 UTC by GLSAMaker/CVETool Bot
Modified: 2020-02-24 17:50 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2020-02-24 17:45:44 UTC
CVE-2020-7247 (https://nvd.nist.gov/vuln/detail/CVE-2020-7247):
  smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and
  other products, allows remote attackers to execute arbitrary commands as
  root via a crafted SMTP session, as demonstrated by shell metacharacters in
  a MAIL FROM field. This affects the "uncommented" default configuration. The
  issue exists because of an incorrect return value upon failure of input
  validation.
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2020-02-24 17:50:46 UTC

*** This bug has been marked as a duplicate of bug 707828 ***