Vulnerabilities
Vulnerable Software
Exim:  >> Exim  >> 3.00  Security Vulnerabilities
CVE-2010-4345
Known exploited
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.
CVSS Score
7.8
EPSS Score
0.196
Published
2010-12-14
transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by creating a hard link to another user's file.
CVSS Score
4.4
EPSS Score
0.001
Published
2010-06-07
transports/appendfile.c in Exim before 4.72, when MBX locking is enabled, allows local users to change permissions of arbitrary files or create arbitrary files, and cause a denial of service or possibly gain privileges, via a symlink attack on a lockfile in /tmp/.
CVSS Score
4.4
EPSS Score
0.001
Published
2010-06-07


Contact Us

Shodan ® - All rights reserved