CVE-2010-4345
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.
- Exim
- β€ 4.72
- Fix
- Available
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 18.1% (97th percentile)
- Weakness
- CWE-77
- NVD status
- Analyzed
- Published
- 2010-12-14
CVE-2010-4345 at NVD
5 known exploits for CVE-2010-4345
Proof-of-concept code and exploit modules indexed by Sploitus