CVE-2010-4345: Exim Privilege Escalation Vulnerability
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spooldirectory directive.
Other sources
Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.
— CISA
See bug #661756 http://www.exim.org/lurker/message/20101207.215955.bb32d4f2.en.html
" Secondly a privilege escalation where the trusted 'exim' user is able to tell Exim to use arbitrary config files, in which further ${run ...} commands will be invoked as root.
The latter should be addressed by the patch at http://lists.exim.org/lurker/message/20101209.172233.abcba158.en.html "
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4345?
CVE-2010-4345 has a high severity level due to its potential for local privilege escalation.
How do I fix CVE-2010-4345?
To fix CVE-2010-4345, upgrade Exim to version 4.72 or later, where the vulnerability has been resolved.
What are the affected versions of Exim in CVE-2010-4345?
CVE-2010-4345 affects Exim versions 4.72 and earlier.
Who is at risk for CVE-2010-4345?
Local users on systems that run affected versions of Exim are at risk for CVE-2010-4345.
What type of vulnerability is CVE-2010-4345?
CVE-2010-4345 is a local privilege escalation vulnerability.