VYPR
High severity7.5NVD Advisory· Published Dec 24, 2020· Updated Jun 17, 2026

CVE-2020-35680

CVE-2020-35680

Description

smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted pattern of client activity, because the filter state machine does not properly maintain the I/O channel between the SMTP engine and the filters layer.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • cpe:2.3:a:opensmtpd:opensmtpd:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:opensmtpd:opensmtpd:*:*:*:*:*:*:*:*range: <6.8.0
    • cpe:2.3:a:opensmtpd:opensmtpd:6.8.0:-:*:*:*:*:*:*
    • cpe:2.3:a:opensmtpd:opensmtpd:6.8.0:patch1-rc1:*:*:*:*:*:*
    • (no CPE)range: <6.8.0p1
  • cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
  • OpenSMTPD/OpenSMTPDdescription
  • OpenBSD/Srcllm-fuzzy
    Range: <6.8.0p1

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.