DEBIAN-CVE-2011-0017

Source
https://security-tracker.debian.org/tracker/CVE-2011-0017
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2011-0017.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2011-0017
Upstream
Published
2011-02-02T01:00:06Z
Modified
2025-09-25T00:17:19.717414Z
Summary
[none]
Details

The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows local users to append log data to arbitrary files via a symlink attack.

References

Affected packages

Debian:11 / exim4

Package

Name
exim4
Purl
pkg:deb/debian/exim4?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.72-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / exim4

Package

Name
exim4
Purl
pkg:deb/debian/exim4?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.72-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / exim4

Package

Name
exim4
Purl
pkg:deb/debian/exim4?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.72-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / exim4

Package

Name
exim4
Purl
pkg:deb/debian/exim4?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.72-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}