Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-24mx-4mj6-v64q

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the spool directory (owned by a non-root user), an attacker can write to a /var/spool/exim4/input spool header file, in which a crafted recipient address can indirectly lead to command execution.

Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the spool directory (owned by a non-root user), an attacker can write to a /var/spool/exim4/input spool header file, in which a crafted recipient address can indirectly lead to command execution.

EPSS

Процентиль: 36%
0.00146
Низкий

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 4 лет назад

Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the spool directory (owned by a non-root user), an attacker can write to a /var/spool/exim4/input spool header file, in which a crafted recipient address can indirectly lead to command execution.

CVSS3: 7.8
nvd
больше 4 лет назад

Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the spool directory (owned by a non-root user), an attacker can write to a /var/spool/exim4/input spool header file, in which a crafted recipient address can indirectly lead to command execution.

CVSS3: 7.8
debian
больше 4 лет назад

Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Bec ...

CVSS3: 7.8
fstec
около 5 лет назад

Уязвимость агента пересылки сообщений Exim, связанная с ошибками управления привилегиями, позволяющая нарушителю повысить привилегии в системе

suse-cvrf
больше 4 лет назад

Security update for exim

EPSS

Процентиль: 36%
0.00146
Низкий

Дефекты

CWE-269