CVE-2021-27216

Updated: 2024-11-23 03:50:49.329962

Description:

Exim 4 before 4.94.2 has Execution with Unnecessary Privileges. By leveraging a delete_pid_file race condition, a local user can delete arbitrary files as root. This involves the -oP and -oPX options.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 6.3
CVSS Version 3.x MEDIUM 6.3

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CentOS 6 ELS exim 4.92.3 6.3 MEDIUM Ignored 2021-11-02 14:03:16
CentOS 8.4 ELS exim 4.94.2 6.3 MEDIUM Ignored 2022-02-17 14:41:07
CentOS 8.5 ELS exim 4.94.2 6.3 MEDIUM Ignored 2022-02-17 14:41:06
CloudLinux 6 ELS exim 4.92.3 6.3 MEDIUM Ignored 2021-11-02 14:03:16
Oracle Linux 6 ELS exim 4.92.3 6.3 MEDIUM Ignored 2021-12-30 02:12:40
Ubuntu 16.04 ELS exim 4.86.2 6.3 MEDIUM Released CLSA-2021:1640271821 2021-12-23 11:55:10
Ubuntu 18.04 ELS exim 4.90.1 6.3 MEDIUM Already Fixed 2023-07-04 17:06:56