Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows local users to append log data to arbitrary files via a symlink attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Exim 'log.c'程序本地权限提升漏洞
Vulnerability Description
Exim 是一个开放源代码的免费邮件传送软件,可以在Unix下提供邮件传输代理功能(MTA),由剑桥大学发布和维护。 Exim 4.72及之前版本中的log.c程序中的open_log函数没有检查(1)setuid或者(2)setgid系统调用的返回值。本地用户可以借助符号链接攻击向任意文件追加日志数据。
CVSS Information
N/A
Vulnerability Type
N/A