CVE-2011-0017
Summary
| CVE | CVE-2011-0017 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-02-02 01:00:06 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows local users to append log data to arbitrary files via a symlink attack. |
Risk And Classification
Primary CVSS: v2.0 6.9 from [email protected]
AV:L/AC:M/Au:N/C:C/I:C/A:C
Problem Types: CWE-20 | CWE-59 | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Exim | Exim | 2.10 | All | All | All |
| Application | Exim | Exim | 2.11 | All | All | All |
| Application | Exim | Exim | 2.12 | All | All | All |
| Application | Exim | Exim | 3.00 | All | All | All |
| Application | Exim | Exim | 3.01 | All | All | All |
| Application | Exim | Exim | 3.02 | All | All | All |
| Application | Exim | Exim | 3.03 | All | All | All |
| Application | Exim | Exim | 3.10 | All | All | All |
| Application | Exim | Exim | 3.11 | All | All | All |
| Application | Exim | Exim | 3.12 | All | All | All |
| Application | Exim | Exim | 3.13 | All | All | All |
| Application | Exim | Exim | 3.14 | All | All | All |
| Application | Exim | Exim | 3.15 | All | All | All |
| Application | Exim | Exim | 3.16 | All | All | All |
| Application | Exim | Exim | 3.20 | All | All | All |
| Application | Exim | Exim | 3.21 | All | All | All |
| Application | Exim | Exim | 3.22 | All | All | All |
| Application | Exim | Exim | 3.30 | All | All | All |
| Application | Exim | Exim | 3.31 | All | All | All |
| Application | Exim | Exim | 3.32 | All | All | All |
| Application | Exim | Exim | 3.33 | All | All | All |
| Application | Exim | Exim | 3.34 | All | All | All |
| Application | Exim | Exim | 3.35 | All | All | All |
| Application | Exim | Exim | 3.36 | All | All | All |
| Application | Exim | Exim | 4.00 | All | All | All |
| Application | Exim | Exim | 4.01 | All | All | All |
| Application | Exim | Exim | 4.02 | All | All | All |
| Application | Exim | Exim | 4.03 | All | All | All |
| Application | Exim | Exim | 4.04 | All | All | All |
| Application | Exim | Exim | 4.05 | All | All | All |
| Application | Exim | Exim | 4.10 | All | All | All |
| Application | Exim | Exim | 4.11 | All | All | All |
| Application | Exim | Exim | 4.12 | All | All | All |
| Application | Exim | Exim | 4.14 | All | All | All |
| Application | Exim | Exim | 4.20 | All | All | All |
| Application | Exim | Exim | 4.21 | All | All | All |
| Application | Exim | Exim | 4.22 | All | All | All |
| Application | Exim | Exim | 4.23 | All | All | All |
| Application | Exim | Exim | 4.24 | All | All | All |
| Application | Exim | Exim | 4.30 | All | All | All |
| Application | Exim | Exim | 4.31 | All | All | All |
| Application | Exim | Exim | 4.32 | All | All | All |
| Application | Exim | Exim | 4.33 | All | All | All |
| Application | Exim | Exim | 4.34 | All | All | All |
| Application | Exim | Exim | 4.40 | All | All | All |
| Application | Exim | Exim | 4.41 | All | All | All |
| Application | Exim | Exim | 4.42 | All | All | All |
| Application | Exim | Exim | 4.43 | All | All | All |
| Application | Exim | Exim | 4.44 | All | All | All |
| Application | Exim | Exim | 4.50 | All | All | All |
| Application | Exim | Exim | 4.51 | All | All | All |
| Application | Exim | Exim | 4.52 | All | All | All |
| Application | Exim | Exim | 4.53 | All | All | All |
| Application | Exim | Exim | 4.54 | All | All | All |
| Application | Exim | Exim | 4.60 | All | All | All |
| Application | Exim | Exim | 4.61 | All | All | All |
| Application | Exim | Exim | 4.62 | All | All | All |
| Application | Exim | Exim | 4.63 | All | All | All |
| Application | Exim | Exim | 4.64 | All | All | All |
| Application | Exim | Exim | 4.65 | All | All | All |
| Application | Exim | Exim | 4.66 | All | All | All |
| Application | Exim | Exim | 4.67 | All | All | All |
| Application | Exim | Exim | 4.68 | All | All | All |
| Application | Exim | Exim | 4.69 | All | All | All |
| Application | Exim | Exim | 4.70 | All | All | All |
| Application | Exim | Exim | 4.71 | All | All | All |
| Application | Exim | Exim | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-2154-1 exim4 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| USN-1060-1: Exim vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| osvdb.org/70696 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Exim "open_log()" Privilege Escalation Security Issue - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| ftp.exim.org/pub/exim/ChangeLogs/ChangeLog-4.74 | af854a3a-2127-422b-91ae-364da2661108 | ftp.exim.org | |
| Debian update for exim4 - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [exim-announce] Exim 4.74 Release | af854a3a-2127-422b-91ae-364da2661108 | lists.exim.org | Patch |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2011:004 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Exim 'log.c' Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Security Advisory SA43243 - Ubuntu update for exim4 - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.