VYPR
Medium severity4.7NVD Advisory· Published Feb 25, 2020· Updated Jun 17, 2026

CVE-2020-8793

CVE-2020-8793

Description

OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:a:opensmtpd:opensmtpd:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:opensmtpd:opensmtpd:*:*:*:*:*:*:*:*range: <6.6.4
    • (no CPE)range: <6.6.4
  • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*+ 1 more
    • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
  • OpenSMTPD/OpenSMTPDdescription

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.