CVE Vulnerabilities

CVE-2014-2972

Published: Sep 04, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

expand.c in Exim before 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and execute arbitrary commands via a crafted lookup value.

Affected Software

NameVendorStart VersionEnd Version
EximExim*4.82.1 (including)
EximExim4.00 (including)4.00 (including)
EximExim4.01 (including)4.01 (including)
EximExim4.02 (including)4.02 (including)
EximExim4.03 (including)4.03 (including)
EximExim4.04 (including)4.04 (including)
EximExim4.05 (including)4.05 (including)
EximExim4.10 (including)4.10 (including)
EximExim4.11 (including)4.11 (including)
EximExim4.12 (including)4.12 (including)
EximExim4.14 (including)4.14 (including)
EximExim4.20 (including)4.20 (including)
EximExim4.21 (including)4.21 (including)
EximExim4.22 (including)4.22 (including)
EximExim4.23 (including)4.23 (including)
EximExim4.24 (including)4.24 (including)
EximExim4.30 (including)4.30 (including)
EximExim4.31 (including)4.31 (including)
EximExim4.32 (including)4.32 (including)
EximExim4.33 (including)4.33 (including)
EximExim4.34 (including)4.34 (including)
EximExim4.40 (including)4.40 (including)
EximExim4.41 (including)4.41 (including)
EximExim4.42 (including)4.42 (including)
EximExim4.43 (including)4.43 (including)
EximExim4.44 (including)4.44 (including)
EximExim4.50 (including)4.50 (including)
EximExim4.51 (including)4.51 (including)
EximExim4.52 (including)4.52 (including)
EximExim4.53 (including)4.53 (including)
EximExim4.54 (including)4.54 (including)
EximExim4.60 (including)4.60 (including)
EximExim4.61 (including)4.61 (including)
EximExim4.62 (including)4.62 (including)
EximExim4.63 (including)4.63 (including)
EximExim4.64 (including)4.64 (including)
EximExim4.65 (including)4.65 (including)
EximExim4.66 (including)4.66 (including)
EximExim4.67 (including)4.67 (including)
EximExim4.68 (including)4.68 (including)
EximExim4.69 (including)4.69 (including)
EximExim4.70 (including)4.70 (including)
EximExim4.71 (including)4.71 (including)
EximExim4.72 (including)4.72 (including)
EximExim4.73 (including)4.73 (including)
EximExim4.74 (including)4.74 (including)
EximExim4.75 (including)4.75 (including)
EximExim4.76 (including)4.76 (including)
EximExim4.77 (including)4.77 (including)
EximExim4.80 (including)4.80 (including)
EximExim4.80.1 (including)4.80.1 (including)
EximExim4.82 (including)4.82 (including)
Exim4Ubuntuesm-infra-legacy/trusty*
Exim4Ubuntulucid*
Exim4Ubuntuprecise*
Exim4Ubuntutrusty*
Exim4Ubuntutrusty/esm*
Exim4Ubuntuupstream*

References