PT-2016-4852 · Exim+3 · Exim+3

Dawid Golunski

·

Published

2016-03-02

·

Updated

2024-06-15

·

CVE-2016-1531

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Exim versions prior to 4.86.2
Description The issue allows local users to gain privileges through the perl startup argument when Exim is installed setuid root.
Recommendations For versions prior to 4.86.2, update to version 4.86.2 or later to resolve the issue. As a temporary workaround, consider disabling the setuid root installation of Exim until a patch is available. Restrict access to the perl startup argument to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1409
CVE-2016-1531
DSA-3517-1
OPENSUSE-SU-2016_0721-1
OPENSUSE-SU-2017_2289-1
OPENSUSE-SU-2024:10017-1
USN-2933-1

Affected Products

Alt Linux
Exim
Suse
Ubuntu