First published: Mon Nov 11 2019(Updated: )
maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Mailutils | <3.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18862 is classified as a local privilege escalation vulnerability due to the setuid installation of maidag in GNU Mailutils.
To mitigate CVE-2019-18862, upgrade GNU Mailutils to version 3.8 or later.
CVE-2019-18862 affects GNU Mailutils versions prior to 3.8, specifically installed with setuid permissions.
CVE-2019-18862 can be exploited by local attackers who have access to the system where GNU Mailutils is installed.
Exploitation of CVE-2019-18862 can lead to unauthorized escalation of privileges on affected systems.