CVE-2010-2024Race Condition in Exim

Severity
4.4MEDIUMNVD
EPSS
0.2%
top 61.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 7
Latest updateOct 29

Description

transports/appendfile.c in Exim before 4.72, when MBX locking is enabled, allows local users to change permissions of arbitrary files or create arbitrary files, and cause a denial of service or possibly gain privileges, via a symlink attack on a lockfile in /tmp/.

CVSS vector

AV:L/AC:M/C:P/I:P/A:PExploitability: 3.4 | Impact: 6.4

Affected Packages2 packages

debiandebian/exim4< exim4 4.72-1 (bookworm)
NVDexim/exim4.71+32

Patches

🔴Vulnerability Details

3
GHSA
GHSA-rwch-4jch-mjx7: transports/appendfile2022-05-14
OSV
CVE-2010-2024: transports/appendfile2010-06-07
CVEList
CVE-2010-2024: transports/appendfile2010-06-07

📋Vendor Advisories

4
Red Hat
kernel: x86/bugs: Use code segment selector for VERW operand2024-10-29
Ubuntu
Exim vulnerabilities2011-02-10
Red Hat
exim: race condition when MBX locking is enabled2010-06-03
Debian
CVE-2010-2024: exim4 - transports/appendfile.c in Exim before 4.72, when MBX locking is enabled, allows...2010

💬Community

2
Bugzilla
CVE-2010-2024 exim: race condition when MBX locking is enabled2010-06-03
Bugzilla
CVE-2010-1238 MoinMoin textcha bypass flaw2010-04-07