CVE-2010-4345
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Exim Privilege Escalation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 18% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-77
מוצרים מושפעים
exim: exim; opensuse: opensuse; debian: debian linux; canonical: ubuntu linux
קישורים
- http://secunia.com/advisories/42576 Broken LinkVendor Advisory
- http://www.exim.org/lurker/message/20101207.215955.bb32d4f2.en.html Mailing ListVendor Advisory
- http://www.vupen.com/english/advisories/2010/3171 Broken LinkVendor Advisory
- http://www.vupen.com/english/advisories/2010/3204 Broken LinkVendor Advisory
- http://secunia.com/advisories/42576 Broken LinkVendor Advisory
- http://www.exim.org/lurker/message/20101207.215955.bb32d4f2.en.html Mailing ListVendor Advisory
- http://www.vupen.com/english/advisories/2010/3171 Broken LinkVendor Advisory
- http://www.vupen.com/english/advisories/2010/3204 Broken LinkVendor Advisory
- http://bugs.exim.org/show_bug.cgi?id=1044 Issue TrackingPatch
- http://lists.exim.org/lurker/message/20101209.172233.abcba158.en.html Mailing ListPatch