CVE-2011-0017
Publication date 1 February 2011
Last updated 24 July 2024
Ubuntu priority
The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows local users to append log data to arbitrary files via a symlink attack.
Status
Package | Ubuntu Release | Status |
---|---|---|
exim4 | ||
Notes
References
Related Ubuntu Security Notices (USN)
- USN-1060-1
- Exim vulnerabilities
- 10 February 2011