Upstream information

CVE-2010-2024 at MITRE

Description

transports/appendfile.c in Exim before 4.72, when MBX locking is enabled, allows local users to change permissions of arbitrary files or create arbitrary files, and cause a denial of service or possibly gain privileges, via a symlink attack on a lockfile in /tmp/.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 4.4
Vector AV:L/AC:M/Au:N/C:P/I:P/A:P
Access Vector Local
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
SUSE Bugzilla entry: 612549 [RESOLVED / FIXED]

SUSE Security Advisories:

  • SUSE-SR:2010:014, published Mon, 02 Aug 2010 15:00:00 +0000
  • openSUSE-SU-2010:0416-1

List of released packages

Product(s) Fixed package version(s) References
openSUSE Tumbleweed
  • exim >= 4.86.2-2.2
  • eximon >= 4.86.2-2.2
  • eximstats-html >= 4.86.2-2.2
Patchnames:
openSUSE Tumbleweed GA exim-4.86.2-2.2


SUSE Timeline for this CVE

CVE page created: Fri Jun 28 07:23:48 2013
CVE page last modified: Fri Dec 8 16:40:24 2023