Exim 4 before 4.94.2 allows Out-of-bounds Write because the main function, while setuid root, copies the current working directory pathname into a buffer that is too small (on some common platforms).
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.exim.org/static/doc/security/CVE-2020-qualys/CVE-2020-28010-SLCWD.txt | vendor advisory |
http://www.openwall.com/lists/oss-security/2021/07/22/7 | third party advisory mailing list |