Description: | Summary: The remote host is missing an update for the 'exim4' package(s) announced via the USN-1060-1 advisory.
Vulnerability Insight: It was discovered that Exim contained a design flaw in the way it processed alternate configuration files. An attacker that obtained privileges of the 'Debian-exim' user could use an alternate configuration file to obtain root privileges. (CVE-2010-4345)
It was discovered that Exim incorrectly handled certain return values when handling logging. An attacker that obtained privileges of the 'Debian-exim' user could use this flaw to obtain root privileges. (CVE-2011-0017)
Dan Rosenberg discovered that Exim incorrectly handled writable sticky-bit mail directories. If Exim were configured in this manner, a local user could use this flaw to cause a denial of service or possibly gain privileges. This issue only applied to Ubuntu 6.06 LTS, 8.04 LTS, 9.10, and 10.04 LTS. (CVE-2010-2023)
Dan Rosenberg discovered that Exim incorrectly handled MBX locking. If Exim were configured in this manner, a local user could use this flaw to cause a denial of service or possibly gain privileges. This issue only applied to Ubuntu 6.06 LTS, 8.04 LTS, 9.10, and 10.04 LTS. (CVE-2010-2024)
Affected Software/OS: 'exim4' package(s) on Ubuntu 6.06, Ubuntu 8.04, Ubuntu 9.10, Ubuntu 10.04, Ubuntu 10.10.
Solution: Please install the updated package(s).
CVSS Score: 6.9
CVSS Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C
|