transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by creating a hard link to another user's file.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade exim4 | Jul 30, 2024 | Jun 7, 2010 |
| Exim | — | Upgrade Exim to version 4.71.0 | Dec 3, 2019 | Jun 7, 2010 |
| Gentoo Linux | — | Upgrade mail-mta/exim. | Oct 30, 2017 | Jun 7, 2010 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 3, 2010 |
| Suse | — | Upgrade eximonUpgrade eximstats-htmlUpgrade exim | Feb 17, 2015 | Jun 7, 2010 |
| Ubuntu | — | Upgrade exim4-daemon-lightUpgrade exim4-daemon-heavyUpgrade exim4-daemon-custom | Nov 8, 2024 | Jun 7, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub