The good news is that the bug was introduced in the OpenSMTPD code in May 2018 and that many distros may still use older library versions, not affected by this issue. For example, only in-dev Debian releases are affected by this issue, but not Debian stable branches, which ship with older OpenSMTPD versions.
CVE-2020-7247 RCE flaw in OpenSMTPD library affects many BSD and Linux distros
2ff7e9595c
Comments