VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-2024
exim: transports/appendfile.c in Exim before 4.72, when M...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2024

Original

transports/appendfile.c in Exim before 4.72, when MBX locking is enabled, allows local users to change permissions of arbitrary files or create arbitrary files, and cause a denial of service or possibly gain privileges, via a symlink attack on a lockfile in /tmp/.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-06-07
Source Information Category:
Advisory, Alert
Last Updated:
2010-06-08




Affected Product Tags
cpe:/a:exim:exim:4.10
cpe:/a:exim:exim:4.20
cpe:/a:exim:exim:4.21
cpe:/a:exim:exim:4.22
cpe:/a:exim:exim:4.23
cpe:/a:exim:exim:4.24
cpe:/a:exim:exim:4.30
cpe:/a:exim:exim:4.31
cpe:/a:exim:exim:4.32
cpe:/a:exim:exim:4.33
cpe:/a:exim:exim:4.34
cpe:/a:exim:exim:4.40
cpe:/a:exim:exim:4.41
cpe:/a:exim:exim:4.42
cpe:/a:exim:exim:4.43
cpe:/a:exim:exim:4.44
cpe:/a:exim:exim:4.50
cpe:/a:exim:exim:4.51
cpe:/a:exim:exim:4.52
cpe:/a:exim:exim:4.53
cpe:/a:exim:exim:4.54
cpe:/a:exim:exim:4.60
cpe:/a:exim:exim:4.61
cpe:/a:exim:exim:4.62
cpe:/a:exim:exim:4.63
cpe:/a:exim:exim:4.64
cpe:/a:exim:exim:4.65
cpe:/a:exim:exim:4.66
cpe:/a:exim:exim:4.67
cpe:/a:exim:exim:4.68
cpe:/a:exim:exim:4.69
cpe:/a:exim:exim:4.70
cpe:/a:exim:exim:4.71 and previous versions
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

X Local [?]
Adjacent Network [?]
Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
X Medium [?]
Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

Alternatives




References
CONFIRM http://vcs.exim.org/viewvc/exim/exim-src/src/transports/appendfile.c?r1=1.25&r2=1.26




CONFIRM http://bugs.exim.org/show_bug.cgi?id=989




CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=600097




CONFIRM http://vcs.exim.org/viewvc/exim/exim-doc/doc-txt/ChangeLog?view=markup&pathrev=exim-4_72_RC2




FULLDISC 20100603 Multiple vulnerabilities in Exim




MLIST [exim-dev] 20100524 Security issues in exim4 local delivery




SECUNIA 40019




Vulnerability Type Race Conditions (CWE-362)




XF exim-mbx-symlink(59042)





Copyright © 2010 JPCERT/CC All Rights Reserved.