VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-2023
exim: transports/appendfile.c in Exim before 4.72, when a...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2023

Original

transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by creating a hard link to another user's file.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-06-07
Source Information Category:
Advisory, Alert
Last Updated:
2010-06-07




Affected Product Tags
cpe:/a:exim:exim:4.10
cpe:/a:exim:exim:4.20
cpe:/a:exim:exim:4.21
cpe:/a:exim:exim:4.22
cpe:/a:exim:exim:4.23
cpe:/a:exim:exim:4.24
cpe:/a:exim:exim:4.30
cpe:/a:exim:exim:4.31
cpe:/a:exim:exim:4.32
cpe:/a:exim:exim:4.33
cpe:/a:exim:exim:4.34
cpe:/a:exim:exim:4.40
cpe:/a:exim:exim:4.41
cpe:/a:exim:exim:4.42
cpe:/a:exim:exim:4.43
cpe:/a:exim:exim:4.44
cpe:/a:exim:exim:4.50
cpe:/a:exim:exim:4.51
cpe:/a:exim:exim:4.52
cpe:/a:exim:exim:4.53
cpe:/a:exim:exim:4.54
cpe:/a:exim:exim:4.60
cpe:/a:exim:exim:4.61
cpe:/a:exim:exim:4.62
cpe:/a:exim:exim:4.63
cpe:/a:exim:exim:4.64
cpe:/a:exim:exim:4.65
cpe:/a:exim:exim:4.66
cpe:/a:exim:exim:4.67
cpe:/a:exim:exim:4.68
cpe:/a:exim:exim:4.69
cpe:/a:exim:exim:4.70
cpe:/a:exim:exim:4.71 and previous versions
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

X Local [?]
Adjacent Network [?]
Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
X Medium [?]
Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

Alternatives




References
BID 40451




CONFIRM http://vcs.exim.org/viewvc/exim/exim-src/src/transports/appendfile.c?r1=1.24&r2=1.25




CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=600093




CONFIRM http://vcs.exim.org/viewvc/exim/exim-doc/doc-txt/ChangeLog?view=markup&pathrev=exim-4_72_RC2




CONFIRM http://bugs.exim.org/show_bug.cgi?id=988




FULLDISC 20100603 Multiple vulnerabilities in Exim




MLIST [exim-dev] 20100524 Security issues in exim4 local delivery




SECUNIA 40019




Vulnerability Type Race Conditions (CWE-362)




XF exim-mail-directory-priv-escalation(59043)





Copyright © 2010 JPCERT/CC All Rights Reserved.