The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows local users to append log data to arbitrary files via a symlink attack.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade exim4 | Jul 30, 2024 | Feb 2, 2011 |
| Exim | — | Upgrade Exim to version 4.72.0 | Dec 3, 2019 | Feb 2, 2011 |
| Freebsd | — | Upgrade eximUpgrade exim-mysqlUpgrade exim-postgresqlUpgrade exim-ldap2Upgrade exim-sa-eximUpgrade exim-ldap | Dec 10, 2025 | Feb 10, 2011 |
| Gentoo Linux | — | Upgrade mail-mta/exim. | Oct 30, 2017 | Feb 1, 2011 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 25, 2011 |
| Suse | — | Upgrade eximonUpgrade eximUpgrade eximstats-html | Feb 17, 2015 | Feb 1, 2011 |
| Ubuntu | — | Upgrade exim4-daemon-customUpgrade exim4-daemon-lightUpgrade exim4-daemon-heavy | Nov 8, 2024 | Feb 2, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub