Vulnerability Description
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Exim | Exim | <= 4.72 |
| Opensuse | Opensuse | 11.1 |
| Debian | Debian Linux | 5.0 |
| Canonical | Ubuntu Linux | 6.06 |
Related Weaknesses (CWE)
References
- http://bugs.exim.org/show_bug.cgi?id=1044Issue TrackingPatch
- http://lists.exim.org/lurker/message/20101209.172233.abcba158.en.htmlMailing ListPatch
- http://lists.exim.org/lurker/message/20101210.164935.385e04d0.en.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00003.htmlMailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2010/12/10/1Mailing List
- http://secunia.com/advisories/42576Broken LinkVendor Advisory
- http://secunia.com/advisories/42930Broken Link
- http://secunia.com/advisories/43128Broken Link
- http://secunia.com/advisories/43243Broken Link
- http://www.cpanel.net/2010/12/critical-exim-security-update.htmlBroken Link
- http://www.debian.org/security/2010/dsa-2131Mailing ListThird Party Advisory
- http://www.debian.org/security/2011/dsa-2154Mailing ListThird Party Advisory
- http://www.exim.org/lurker/message/20101207.215955.bb32d4f2.en.htmlMailing ListVendor Advisory
- http://www.kb.cert.org/vuls/id/758489Third Party AdvisoryUS Government Resource
- http://www.metasploit.com/modules/exploit/unix/smtp/exim4_string_formatThird Party Advisory
FAQ
What is CVE-2010-4345?
CVE-2010-4345 is a vulnerability with a CVSS score of 7.8 (HIGH). Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary comma...
How severe is CVE-2010-4345?
CVE-2010-4345 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-4345?
Check the references section above for vendor advisories and patch information. Affected products include: Exim Exim, Opensuse Opensuse, Debian Debian Linux, Canonical Ubuntu Linux.