PT-2021-3127 · Exim+3 · Exim+3

Published

2021-05-04

·

Updated

2022-07-18

·

CVE-2021-27216

CVSS v3.1

6.3

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Exim versions prior to 4.94.2
Description The issue is related to errors in privilege management. It allows an attacker to delete arbitrary files in the system by leveraging a delete pid file race condition. This can be done using the -oP and -oPX options. A local user can exploit this to delete files as root.
Recommendations For Exim versions prior to 4.94.2, update to version 4.94.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the -oP and -oPX options to minimize the risk of exploitation.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1764
ALT-PU-2022-2269
BDU:2021-02750
CVE-2021-27216
USN-4934-1
USN-4934-2

Affected Products

Alt Linux
Exim
Linuxmint
Ubuntu