Privilege escalation in Exim - CVE-2010-4345

 

Privilege escalation in Exim - CVE-2010-4345

Published: August 22, 2016 / Updated: March 25, 2022


Vulnerability identifier: #VU341
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L]
CVE-ID: CVE-2010-4345
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local user to escalate privileges on vulnerable system.

The vulnerability exists due to design error in Exim, when allowing local users to load arbitrary configuration file via the "spool_directory" directive. A local user can specify an alternate configuration file with a directive that contains arbitrary commands and execute arbitrary commands on the system with root privileges.

Successful exploitation of this vulnerability will allow a local user to gain root privileges on the system.


Affected software

Exim
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Fedora
Opensuse
exim

How to mitigate CVE-2010-4345

Update to version 4.73.

exim - update to 4.72-2.el6

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins