CVE-2020-28019

HIGH

Exim 4.88-4.94.1 - Improper Initialization via BDAT Command

Title source: llm
STIX 2.1

Description

Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences. This occurs because use of certain getc functions is mishandled when a client uses BDAT instead of DATA.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.6106
EPSS Percentile 99.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-665
Status published
Products (1)
exim/exim 4.88 - 4.94.2
Published May 06, 2021
Tracked Since Feb 18, 2026