Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Exim | Exim | * | 4.72 (including) |
Red Hat Enterprise Linux 4 | RedHat | exim-0:4.43-1.RHEL4.5.el4_8.3 | * |
Red Hat Enterprise Linux 5 | RedHat | exim-0:4.63-5.el5_6.2 | * |
Exim4 | Ubuntu | dapper | * |
Exim4 | Ubuntu | hardy | * |
Exim4 | Ubuntu | karmic | * |
Exim4 | Ubuntu | lucid | * |
Exim4 | Ubuntu | maverick | * |
Exim4 | Ubuntu | upstream | * |