CVE-2020-28025: Exim
High severity, CVSS 7.5. EPSS: 2.8% chance of exploitation in the next 30 days.
Exim 4 before 4.94.2 allows Out-of-bounds Read because pdkim_finish_bodyhash does not validate the relationship between sig->bodyhash.len and b->bh.len; thus, a crafted DKIM-Signature header might lead to a leak of sensitive information from process memory.
Affected products
- Exim Exim: from 4.00, before 4.94.2 (fixed in 4.94.2)
Published 2021-05-06. Last modified 2026-06-17.