It was discovered that OpenSMTPD incorrectly verified the sender's or receiver's e-mail addresses under certain conditions. An attacker could use this vulnerability to execute arbitrary commands as root.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "opensmtpd", "binary_version": "6.0.3p1-1ubuntu0.1" }, { "binary_name": "opensmtpd-dbgsym", "binary_version": "6.0.3p1-1ubuntu0.1" } ] }