groups.yahoo.comConfirmation
http://groups.yahoo.com/group/exim-users/message/42358 CVE-2002-1381
Exim Internet Mailer 3.35/3.36/4.10 - Format String
Record summary
CVE-2002-1381 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBExim Internet Mailer 3.35/3.36/4.10 - Format StringExploitDB exploitby Thomas WanaNot analyzed1 file
References
720021204 Local root vulnerability found in exim 4.x (and 3.x)mailing list
http://marc.info/?l=bugtraq&m=103903403527788&w=2 GLSA-200212-5Vendor advisory
http://marc.info/?l=bugtraq&m=104006219018664&w=2 [Exim] 20021204 Minor security problem in both Exim 3 and 4mailing list
http://www.exim.org/pipermail/exim-users/Week-of-Mon-20021202/046978.html 6314vdb entry
http://www.securityfocus.com/bid/6314 exim-daemonc-format-string(10761)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/10761 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-1381