CVE-2011-0017
Last modified
CVE-2011-0017 is a vulnerability of currently unknown severity. The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows local users to append log data to arbitrary files via a symlink attack.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows local users to append log data to arbitrary files via a symlink attack.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Exim | Exim | <= 4.72 |
| Exim | Exim | 2.10 |
| Exim | Exim | 2.11 |
| Exim | Exim | 2.12 |
| Exim | Exim | 3.00 |
| Exim | Exim | 3.01 |
| Exim | Exim | 3.02 |
| Exim | Exim | 3.03 |
| Exim | Exim | 3.10 |
| Exim | Exim | 3.11 |
| Exim | Exim | 3.12 |
| Exim | Exim | 3.13 |
| Exim | Exim | 3.14 |
| Exim | Exim | 3.15 |
| Exim | Exim | 3.16 |
| Exim | Exim | 3.20 |
| Exim | Exim | 3.21 |
| Exim | Exim | 3.22 |
| Exim | Exim | 3.30 |
| Exim | Exim | 3.31 |
| Exim | Exim | 3.32 |
| Exim | Exim | 3.33 |
| Exim | Exim | 3.34 |
| Exim | Exim | 3.35 |
| Exim | Exim | 3.36 |
| Exim | Exim | 4.00 |
| Exim | Exim | 4.01 |
| Exim | Exim | 4.02 |
| Exim | Exim | 4.03 |
| Exim | Exim | 4.04 |
| Exim | Exim | 4.05 |
| Exim | Exim | 4.10 |
| Exim | Exim | 4.11 |
| Exim | Exim | 4.12 |
| Exim | Exim | 4.14 |
| Exim | Exim | 4.20 |
| Exim | Exim | 4.21 |
| Exim | Exim | 4.22 |
| Exim | Exim | 4.23 |
| Exim | Exim | 4.24 |
| Exim | Exim | 4.30 |
| Exim | Exim | 4.31 |
| Exim | Exim | 4.32 |
| Exim | Exim | 4.33 |
| Exim | Exim | 4.34 |
| Exim | Exim | 4.40 |
| Exim | Exim | 4.41 |
| Exim | Exim | 4.42 |
| Exim | Exim | 4.43 |
| Exim | Exim | 4.44 |
Showing 50 of 67 affected configurations. See NVD for the full list.
References
- http://secunia.com/advisories/43101Vendor Advisory
- http://secunia.com/advisories/43128Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0224Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0245Vendor Advisory
- http://secunia.com/advisories/43101Vendor Advisory
- http://secunia.com/advisories/43128Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0224Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0245Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-0017?
How severe is CVE-2011-0017?
How do I fix CVE-2011-0017?
Are you affected by CVE-2011-0017?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
