UNIX symbolic link following in Exim - CVE-2020-28007

 

UNIX symbolic link following in Exim - CVE-2020-28007

Published: May 4, 2021


Vulnerability identifier: #VU52853
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-28007
CWE-ID: CWE-61
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a symlink following issue in Exim log directory. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.

Successful exploitation of this vulnerability may result in privilege escalation.


Affected software

Exim
Amazon Linux AMI
Gentoo Linux
Ubuntu
exim4 (Debian package)
exim4-daemon-light (Ubuntu package)
exim4-daemon-heavy (Ubuntu package)
exim4-base (Ubuntu package)
exim

How to mitigate CVE-2020-28007

Install updates from vendor's website.

Exim - update to 4.94.2
exim4 (Debian package) - update to 4.92-8+deb10u6
exim4-daemon-light (Ubuntu package) - addressed in versions 4.86.22ubuntu2.6+esm1, 4.90.1-1ubuntu1.8, 4.93-13ubuntu1.5, 4.94-7ubuntu1.2, 4.94-15ubuntu1.2
exim4-daemon-heavy (Ubuntu package) - addressed in versions 4.86.22ubuntu2.6+esm1, 4.90.1-1ubuntu1.8, 4.93-13ubuntu1.5, 4.94-7ubuntu1.2, 4.94-15ubuntu1.2
exim4-base (Ubuntu package) - addressed in versions 4.86.22ubuntu2.6+esm1, 4.90.1-1ubuntu1.8, 4.93-13ubuntu1.5, 4.94-7ubuntu1.2, 4.94-15ubuntu1.2
exim - update to 4.92-1.33

External References

Related Security Bulletins