Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2020-8793Time-of-check Time-of-use (TOCTOU) Race Condition in Opensmtpd

Severity
4.7MEDIUMNVD
OSV9.8
EPSS
0.8%
top 26.15%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedFeb 25
Latest updateMay 24

Description

OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.0 | Impact: 3.6

Affected Packages3 packages

NVDopensmtpd/opensmtpd< 6.6.4
Debianopensmtpd/opensmtpd< 6.6.4p1-1+3
Ubuntuopensmtpd/opensmtpd< 6.0.3p1-1ubuntu0.2+2

Also affects: Ubuntu Linux 18.04, 19.10, Fedora 32

🔴Vulnerability Details

5
GHSA
GHSA-m2cf-xghm-rxmc: OpenSMTPD before 62022-05-24
OSV
opensmtpd vulnerabilities2021-03-15
OSV
OpenSMTPD vulnerabilities2020-03-02
CVEList
CVE-2020-8793: OpenSMTPD before 62020-02-25
OSV
CVE-2020-8793: OpenSMTPD before 62020-02-25

💥Exploits & PoCs

1
Exploit-DB
OpenSMTPD 6.6.3 - Arbitrary File Read2020-02-26

📋Vendor Advisories

3
Ubuntu
OpenSMTPD vulnerabilities2021-03-15
Ubuntu
OpenSMTPD vulnerabilities2020-03-02
Debian
CVE-2020-8793: opensmtpd - OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some...2020

🕵️Threat Intelligence

1
Trendmicro
CVE-2020-8794 Can Lead to Privilege Escalation and RCE2020-03-12

💬Community

3
Bugzilla
CVE-2020-8793 opensmtpd: Reading of arbitrary file by unprivileged attacker can result in information disclosure or privilege escalation [epel-all]2020-02-25
Bugzilla
CVE-2020-8793 opensmtpd: Reading of arbitrary file by unprivileged attacker can result in information disclosure or privilege escalation2020-02-25
Bugzilla
CVE-2020-8793 opensmtpd: Reading of arbitrary file by unprivileged attacker can result in information disclosure or privilege escalation [fedora-all]2020-02-25