CVE-2014-2972
Publication date 4 September 2014
Last updated 24 July 2024
Ubuntu priority
expand.c in Exim before 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and execute arbitrary commands via a crafted lookup value.
Status
Package | Ubuntu Release | Status |
---|---|---|
exim4 | ||
14.04 LTS trusty |
Fixed 4.82-3ubuntu2.1
|
|
Notes
References
Related Ubuntu Security Notices (USN)
- USN-2933-1
- Exim vulnerabilities
- 15 March 2016
Other references
- https://lists.exim.org/lurker/message/20140722.152452.d6c019e8.en.html
- https://lists.exim.org/lurker/message/20140722.145949.42c043f5.en.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136264.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136251.html
- https://www.cve.org/CVERecord?id=CVE-2014-2972