CVE-2019-18862: High severity gnu mailutils vulnerability
Published Nov 11, 2019
·Updated
maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.
Affected Software
1 affected component
GNU Mailutils<3.8
Event History
Nov 11, 2019
CVE Published
via MITRE·03:49 PM
Data Sourced
via MITRE·03:49 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-18862?
CVE-2019-18862 is classified as a local privilege escalation vulnerability due to the setuid installation of maidag in GNU Mailutils.
2
How do I fix CVE-2019-18862?
To mitigate CVE-2019-18862, upgrade GNU Mailutils to version 3.8 or later.
3
What systems are affected by CVE-2019-18862?
CVE-2019-18862 affects GNU Mailutils versions prior to 3.8, specifically installed with setuid permissions.
4
Who can exploit CVE-2019-18862?
CVE-2019-18862 can be exploited by local attackers who have access to the system where GNU Mailutils is installed.
5
What are the consequences of CVE-2019-18862?
Exploitation of CVE-2019-18862 can lead to unauthorized escalation of privileges on affected systems.