transports/appendfile.c in Exim before 4.72, when MBX locking is enabled, allows local users to change permissions of arbitrary files or create arbitrary files, and cause a denial of service or possibly gain privileges, via a symlink attack on a lockfile in /tmp/.
CVSS Details
- CVSS 3.1 Base Score: 7.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade exim4 | Jul 30, 2024 | Jun 7, 2010 |
| Exim | — | Upgrade Exim to version 4.71.0 | Dec 3, 2019 | Jun 7, 2010 |
| Gentoo Linux | — | Upgrade mail-mta/exim. | Oct 30, 2017 | Jun 7, 2010 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 3, 2010 |
| Suse | — | Upgrade eximstats-htmlUpgrade eximonUpgrade exim | Feb 17, 2015 | Jun 7, 2010 |
| Ubuntu | — | Upgrade exim4-daemon-lightUpgrade exim4-daemon-customUpgrade exim4-daemon-heavy | Nov 8, 2024 | Jun 7, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub