Vulnerability record · CVE-2020-8794 · published 25 February 2020
CVE-2020-8794: OpenSMTPD out-of-bounds read in mta_io enables remote code execution
Opensmtpd · Opensmtpd
OpenSMTPD before 6.6.4 contains an out-of-bounds read in mta_io in mta_session.c when handling multi-line replies. The flaw affects the client side of OpenSMTPD, but a server can be attacked because the server launches the client code during bounce handling. It matters because it can lead to remote code execution on an internet-facing mail server.
Description
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and very high EPSS plus public exploit references make this a critical patching priority.
What it is
OpenSMTPD before 6.6.4 contains an out-of-bounds read in mta_io in mta_session.c when handling multi-line replies. The flaw affects the client side of OpenSMTPD, but a server can be attacked because the server launches the client code during bounce handling. It matters because it can lead to remote code execution on an internet-facing mail server.
Impact
An attacker can trigger the out-of-bounds read and potentially execute code in the context of the OpenSMTPD process. Given the CVSS vector, this can result in full compromise of confidentiality, integrity and availability.
Attack surface
The vulnerability is network-reachable (AV:N) with no privileges or user interaction required (PR:N, UI:N). It is reached by causing the server to process a crafted multi-line reply through the client code path invoked during bounce handling.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high at 0.889 (99.77th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade OpenSMTPD to 6.6.4 or later, or apply the vendor patch for your distribution (Ubuntu USN-4294-1, Debian DSA-4634, Fedora advisory).
- If immediate patching is not possible, restrict network access to the SMTP service to trusted hosts and disable or limit bounce handling where feasible.
- Monitor vendor advisories for OpenSMTPD, Ubuntu, Debian and Fedora for updated packages and re-apply as needed.
- Verify the running OpenSMTPD version after patching and restart the service to ensure the fixed binary is loaded.
Detection
- Inspect OpenSMTPD logs for crashes, abnormal terminations or restarts that could indicate exploitation attempts.
- Monitor for unexpected child processes or outbound connections spawned by the OpenSMTPD service.
- Use host-based detection to alert on unusual memory access patterns or crashes in the smtpd process.
- Review mail queue and bounce-related activity for anomalous multi-line reply handling or malformed messages.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-8794 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-8794), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.