CVE-2010-4345

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Dec 14, 2010
Updated: Dec 19, 2024

Summary

CVE-2010-4345 is a vulnerability affecting Exim version 4.72 and earlier. This issue allows local users to elevate their privileges by manipulating the exim user account's ability to specify an alternate configuration file. By introducing arbitrary commands in a directive, such as spool_directory, attackers can gain unauthorized access to sensitive system information or even execute malicious code. This vulnerability poses a significant security risk and requires immediate attention from system administrators to patch or mitigate the issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • University Of Cambridge Exim
  • Ubuntu Linux
  • Open SUSE
  • Debian

Affected Vendors

  • Debian
  • Opensuse
  • Canonical System
  • Export-Import Bank of the United States