PT-2020-6049 · Exim+5 · Exim+5
Published
2020-10-20
·
Updated
2024-06-15
·
CVE-2020-28007
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Exim versions prior to 4.94.2
Description
The issue is related to the Exim message transfer agent and involves a problem with symbolic link tracking. An attacker can exploit this by creating a specially crafted symbolic link to a file and overwriting it with application privileges, potentially allowing privilege escalation in the system. This can be achieved because Exim operates as root in the log directory, which is owned by a non-root user, making it vulnerable to symlink or hard link attacks that can overwrite critical root-owned files anywhere on the filesystem.
Recommendations
For Exim versions prior to 4.94.2, update to version 4.94.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the log directory to minimize the risk of exploitation.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Exim
Linuxmint
Suse
Ubuntu