CVE-2002-1381: High severity University Of Cambridge Exim vulnerability
Published Dec 23, 2002
·Updated
Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pidfilepath value.
Affected Software
3 affected components
University Of Cambridge Exim=3.35
University Of Cambridge Exim=3.36
University Of Cambridge Exim=4.10
Remediation
Patch Available
Event History
Dec 23, 2002
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1381?
CVE-2002-1381 is considered to be a high severity vulnerability due to its potential to allow arbitrary code execution by administrative users.
2
How do I fix CVE-2002-1381?
To fix CVE-2002-1381, you should upgrade Exim to a version that is not affected, specifically to Exim 4.10 or later.
3
What versions of Exim are affected by CVE-2002-1381?
CVE-2002-1381 affects Exim versions 3.35 to 3.36 and 4.x up to 4.10.
4
Who is impacted by CVE-2002-1381?
Any administrative users of Exim versions 4.x through 4.10 and 3.x through 3.36 are at risk from CVE-2002-1381.
5
What type of vulnerability is CVE-2002-1381?
CVE-2002-1381 is classified as a format string vulnerability, which can lead to remote code execution.