Medium severity4.7NVD Advisory· Published Feb 25, 2020· Updated Jun 17, 2026
CVE-2020-8793
CVE-2020-8793
Description
OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*+ 1 more
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- OpenSMTPD/OpenSMTPDdescription
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2020/02/24/4nvdExploitMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2020/Feb/28nvdMailing ListThird Party Advisory
- usn.ubuntu.com/4294-1/nvdThird Party Advisory
- www.openbsd.org/security.htmlnvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OPH4QU4DNVHA7ACFXMYFCEP5PSXXPN4E/nvd
News mentions
0No linked articles in our index yet.