First published: Sun Mar 19 2006(Updated: )
Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field that contains a filename separated by whitespace, which is not quoted when greylistclean.cron provides the argument to the rm command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SA-Exim | =4.0 | |
SA-Exim | =4.1 | |
SA-Exim | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1251 is classified as a moderate severity vulnerability due to its ability to allow remote attackers to manipulate file deletion.
To fix CVE-2006-1251, update to version 4.3 or later of sa-exim, which includes a patch for this vulnerability.
Versions 4.0, 4.1, and 4.2 of sa-exim are vulnerable to CVE-2006-1251.
Yes, CVE-2006-1251 can be exploited remotely through crafted email messages.
CVE-2006-1251 allows attackers to delete arbitrary files from the server, potentially leading to data loss.