Vulnerabilities > CVE-2002-1381 - Unspecified vulnerability in University of Cambridge Exim 3.35/3.36/4.10

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
university-of-cambridge
exploit available

Summary

Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value.

Exploit-Db

descriptionExim Internet Mailer 3.35/3.36/4.10 Format String Vulnerability. CVE-2002-1381. Local exploit for linux platform
idEDB-ID:22066
last seen2016-02-02
modified2002-12-04
published2002-12-04
reporterThomas Wana
sourcehttps://www.exploit-db.com/download/22066/
titleExim Internet Mailer 3.35/3.36/4.10 Format String Vulnerability