First published: Sun Mar 19 2006(Updated: )
Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field that contains a filename separated by whitespace, which is not quoted when greylistclean.cron provides the argument to the rm command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SA-Exim | =4.0 | |
SA-Exim | =4.1 | |
SA-Exim | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.