CVE Vulnerabilities

CVE-2010-4345

Published: Dec 14, 2010 | Modified: Oct 22, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 MODERATE
AV:L/AC:L/Au:S/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.

Affected Software

NameVendorStart VersionEnd Version
EximExim*4.72 (including)
Red Hat Enterprise Linux 4RedHatexim-0:4.43-1.RHEL4.5.el4_8.3*
Red Hat Enterprise Linux 5RedHatexim-0:4.63-5.el5_6.2*
Exim4Ubuntudapper*
Exim4Ubuntuhardy*
Exim4Ubuntukarmic*
Exim4Ubuntulucid*
Exim4Ubuntumaverick*
Exim4Ubuntuupstream*

References