Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Exim < 4.72 RC2 Multiple Vulnerabilities

Information

Severity

Severity

Medium

Family

Family

SMTP problems

CVSSv2 Base

CVSSv2 Base

4.4

CVSSv2 Vector

CVSSv2 Vector

AV:L/AC:M/Au:N/C:P/I:P/A:P

Solution Type

Solution Type

Vendor Patch

Created

Created

13 years ago

Modified

Modified

5 years ago

Summary

According to the version from its Banner, the remote Exim is prone to multiple vulnerabilities.

Insight

Insight

1. Exim creates temporary files in an insecure manner. An attacker with local access could potentially exploit this issue to perform symbolic-link attacks. Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible. 2. Exim is prone to a local privilege-escalation vulnerability. Local attackers can exploit this issue to gain elevated privileges on affected computers.

Affected Software

Affected Software

Versions prior to Exim 4.72 RC2 are vulnerable.

Solution

Solution

Updates are available. Please see the references for more information.

Common Vulnerabilities and Exposures (CVE)