Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Notification (DSN). Certain uses of ORCPT= can place a newline into a spool header file, and indirectly allow unauthenticated remote attackers to execute arbitrary commands as root.
[
{
"source": "https://github.com/exim/exim/commit/919111edac911ba9c15422eafd7c5bf14d416d26",
"target": {
"function": "bdat_ungetc",
"file": "src/src/smtp_in.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"digest": {
"function_hash": "85807556721849417698167290800033609961",
"length": 86.0
},
"id": "CVE-2020-28026-a5b97121"
},
{
"source": "https://github.com/exim/exim/commit/919111edac911ba9c15422eafd7c5bf14d416d26",
"target": {
"file": "src/src/smtp_in.c"
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"2970847905863908930961351479348962244",
"259127508678304675853565838131490768076",
"16856440449629165604374376294870505588",
"21031574626938302228709321949938569854",
"66694532801356984293692391694813765468",
"228435147706632689035739186300622821874",
"137018139142916213668559470023354199721",
"262955889687131153967951266340364206508",
"122233694988885115887188843215612136724",
"55546132595750780137850156557040648213",
"178043897109541241882122479475000937559",
"311496951671523793228361465075141960070"
],
"threshold": 0.9
},
"id": "CVE-2020-28026-f33c15e3"
}
]