Beveiligingsadvies

CVE-2011-0017

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2011-02-02 00:00:00
Laatst bijgewerkt 2024-08-06 21:36:02
Toegewezen door redhat
CVSS-score geen score
Status PUBLISHED

Beschrijving

The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows local users to append log data to arbitrary files via a symlink attack.