CVE-2020-11503

A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary code remotely.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:sophos:sfos:*:*:*:*:*:*:*:*
cpe:2.3:o:sophos:sfos:17.5:-:*:*:*:*:*:*
cpe:2.3:o:sophos:sfos:17.5:maintenance_release1:*:*:*:*:*:*
cpe:2.3:o:sophos:sfos:17.5:maintenance_release10:*:*:*:*:*:*
cpe:2.3:o:sophos:sfos:17.5:maintenance_release11:*:*:*:*:*:*
cpe:2.3:o:sophos:sfos:17.5:maintenance_release2:*:*:*:*:*:*
cpe:2.3:o:sophos:sfos:17.5:maintenance_release3:*:*:*:*:*:*
cpe:2.3:o:sophos:sfos:17.5:maintenance_release4:*:*:*:*:*:*
cpe:2.3:o:sophos:sfos:17.5:maintenance_release5:*:*:*:*:*:*
cpe:2.3:o:sophos:sfos:17.5:maintenance_release6:*:*:*:*:*:*
cpe:2.3:o:sophos:sfos:17.5:maintenance_release7:*:*:*:*:*:*
cpe:2.3:o:sophos:sfos:17.5:maintenance_release8:*:*:*:*:*:*
cpe:2.3:o:sophos:sfos:17.5:maintenance_release9:*:*:*:*:*:*
cpe:2.3:h:sophos:xg_firewall:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:58

Type Values Removed Values Added
References () https://community.sophos.com/b/security-blog/posts/advisory-potential-rce-through-heap-overflow-in-awarrensmtp-cve-2020-11503 - Vendor Advisory () https://community.sophos.com/b/security-blog/posts/advisory-potential-rce-through-heap-overflow-in-awarrensmtp-cve-2020-11503 - Vendor Advisory

Information

Published : 2020-06-18 16:15

Updated : 2024-11-21 04:58


NVD link : CVE-2020-11503

Mitre link : CVE-2020-11503

CVE.ORG link : CVE-2020-11503


JSON object : View

Products Affected

sophos

  • sfos
  • xg_firewall
CWE
CWE-787

Out-of-bounds Write