Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qrcj-mq48-333m

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by creating a hard link to another user's file.

transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by creating a hard link to another user's file.

EPSS

Процентиль: 26%
0.00089
Низкий

Дефекты

CWE-362

Связанные уязвимости

ubuntu
больше 15 лет назад

transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by creating a hard link to another user's file.

redhat
больше 15 лет назад

transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by creating a hard link to another user's file.

nvd
больше 15 лет назад

transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by creating a hard link to another user's file.

debian
больше 15 лет назад

transports/appendfile.c in Exim before 4.72, when a world-writable sti ...

EPSS

Процентиль: 26%
0.00089
Низкий

Дефекты

CWE-362