Exim 4.72 and earlier allows local users to gain...
Moderate severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 7, 2025
Description
Published by the National Vulnerability Database
Dec 14, 2010
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 7, 2025
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.
References