CVE-2020-35680
24.12.2020, 16:15
smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted pattern of client activity, because the filter state machine does not properly maintain the I/O channel between the SMTP engine and the filters layer.Enginsight
Vendor | Product | Version |
---|---|---|
opensmtpd | opensmtpd | 𝑥 < 6.8.0 |
opensmtpd | opensmtpd | 6.8.0 |
opensmtpd | opensmtpd | 6.8.0:patch1-rc1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References