First published: Thu May 06 2021(Updated: )
Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the log directory (owned by a non-root user), a symlink or hard link attack allows overwriting critical root-owned files anywhere on the filesystem.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exim Exim | >=4.00<4.94.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-28007.
The severity of CVE-2020-28007 is high with a CVSS score of 7.8.
The affected software is Exim version 4 before 4.94.2.
CVE-2020-28007 allows execution with unnecessary privileges in Exim 4 before 4.94.2, which can lead to overwriting critical root-owned files.
This vulnerability can be exploited through a symlink or hard link attack in the log directory, which allows overwriting critical root-owned files.