Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-2023
HistoryJun 07, 2010 - 12:00 a.m.

CVE-2010-2023

2010-06-0700:00:00
ubuntu.com
ubuntu.com
13

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

10.1%

transports/appendfile.c in Exim before 4.72, when a world-writable
sticky-bit mail directory is used, does not verify the st_nlink field of
mailbox files, which allows local users to cause a denial of service or
possibly gain privileges by creating a hard link to another user’s file.

Bugs

Notes

Author Note
mdeslaur not default configuration
OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchexim4< 4.60-3ubuntu3.3UNKNOWN
ubuntu8.04noarchexim4< 4.69-2ubuntu0.3UNKNOWN
ubuntu9.10noarchexim4< 4.69-11ubuntu4.2UNKNOWN
ubuntu10.04noarchexim4< 4.71-3ubuntu1.1UNKNOWN
ubuntu10.10noarchexim4< 4.72-1ubuntu1UNKNOWN

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

10.1%