It was discovered that OpenSMTPD incorrectly verified the sender's or receiver's e-mail addresses under certain conditions. An attacker could use this vulnerability to execute arbitrary commands as root.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "6.0.3p1-1ubuntu0.1", "binary_name": "opensmtpd" }, { "binary_version": "6.0.3p1-1ubuntu0.1", "binary_name": "opensmtpd-dbgsym" } ] }