Описание
A flaw was found in Exim. This vulnerability allows an attacker to perform directory traversal by mishandling arguments related to queue-name. This could enable unauthorized access to files outside of the designated spool area, potentially leading to a gain of privileges.
Отчет
This Important flaw in Exim allows a local, unprivileged attacker to achieve privilege escalation through directory traversal. By exploiting mishandled queue-name arguments, an attacker can access sensitive files outside the intended spool area, increasing the risk of system compromise.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Дополнительная информация
Статус:
EPSS
8.4 High
CVSS3
Связанные уязвимости
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
Exim before 4.99.5 allows directory traversal to access files outside ...
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
EPSS
8.4 High
CVSS3