Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-66140

Опубликовано: 24 июл. 2026
Источник: debian
EPSS Низкий

Описание

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
exim4fixed4.99.4-2package

Примечания

  • https://www.openwall.com/lists/oss-security/2026/07/22/9

  • https://www.exim.org/static/doc/security/EXIM-Security-2026-06-22.1/EXIM-Security-2026-06-22.1.txt

  • Fixed by: https://code.exim.org/exim/exim/commit/a2ceac7c7e1183f7e35792480cb4a06a71b915ba (exim-4.99.5)

EPSS

Процентиль: 19%
0.00272
Низкий

Связанные уязвимости

CVSS3: 8.4
ubuntu
8 дней назад

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

CVSS3: 8.4
redhat
8 дней назад

A flaw was found in Exim. This vulnerability allows an attacker to perform directory traversal by mishandling arguments related to queue-name. This could enable unauthorized access to files outside of the designated spool area, potentially leading to a gain of privileges.

CVSS3: 8.4
nvd
8 дней назад

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

CVSS3: 8.4
github
8 дней назад

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

EPSS

Процентиль: 19%
0.00272
Низкий
Уязвимость CVE-2026-66140