PT-2021-3127 · Exim+3 · Exim+3
Published
2021-05-04
·
Updated
2022-07-18
·
CVE-2021-27216
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Exim versions prior to 4.94.2
Description
The issue is related to errors in privilege management. It allows an attacker to delete arbitrary files in the system by leveraging a delete pid file race condition. This can be done using the -oP and -oPX options. A local user can exploit this to delete files as root.
Recommendations
For Exim versions prior to 4.94.2, update to version 4.94.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the -oP and -oPX options to minimize the risk of exploitation.
Exploit
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Exim
Linuxmint
Ubuntu