Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-27216

Опубликовано: 06 мая 2021
Источник: debian

Описание

Exim 4 before 4.94.2 has Execution with Unnecessary Privileges. By leveraging a delete_pid_file race condition, a local user can delete arbitrary files as root. This involves the -oP and -oPX options.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
exim4fixed4.94.2-1package
exim4not-affectedbusterpackage
exim4not-affectedstretchpackage

Примечания

  • Introduced by: https://git.exim.org/exim.git/commit/01446a56c76aa5ac3213a86f8992a2371a8301f3 (exim-4_94_RC0)

  • https://www.openwall.com/lists/oss-security/2021/05/04/7

Связанные уязвимости

CVSS3: 6.3
ubuntu
почти 5 лет назад

Exim 4 before 4.94.2 has Execution with Unnecessary Privileges. By leveraging a delete_pid_file race condition, a local user can delete arbitrary files as root. This involves the -oP and -oPX options.

CVSS3: 6.3
nvd
почти 5 лет назад

Exim 4 before 4.94.2 has Execution with Unnecessary Privileges. By leveraging a delete_pid_file race condition, a local user can delete arbitrary files as root. This involves the -oP and -oPX options.

CVSS3: 6.3
github
больше 3 лет назад

Exim 4 before 4.94.2 has Execution with Unnecessary Privileges. By leveraging a delete_pid_file race condition, a local user can delete arbitrary files as root. This involves the -oP and -oPX options.

CVSS3: 3.3
fstec
почти 5 лет назад

Уязвимость агента пересылки сообщений Exim, связанная с ошибками управления привилегиями, позволяющая нарушителю удалять произвольные файлы в системе