CVE-2014-2972
Publication date 4 September 2014
Last updated 24 July 2024
Ubuntu priority
Description
expand.c in Exim before 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and execute arbitrary commands via a crafted lookup value.
Status
Package | Ubuntu Release | Status |
---|---|---|
exim4 | ||
14.04 LTS trusty |
Fixed 4.82-3ubuntu2.1
|
|
Notes
References
Related Ubuntu Security Notices (USN)
- USN-2933-1
- Exim vulnerabilities
- 15 March 2016
Other references
- https://lists.exim.org/lurker/message/20140722.152452.d6c019e8.en.html
- https://lists.exim.org/lurker/message/20140722.145949.42c043f5.en.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136264.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136251.html
- https://www.cve.org/CVERecord?id=CVE-2014-2972