Executive brief
A remote code execution vulnerability exists in OpenSMTPD's smtp_mailaddr function due to incorrect input validation of the MAIL FROM field. Attackers can exploit this via shell metacharacters in a crafted SMTP session to execute arbitrary commands as root in the default configuration.
Affected products
- OpenBSD OpenSMTPD 6.6
- OpenBSD OpenBSD 6.6
Timeline
- 2020-01-28: disclosed: Initial public disclosure via Openwall and Seclists
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-25: exploited: Confirmed as exploited in the wild per CISA KEV entry