4.6
CVSSv2

CVE-2014-2972

Published: 04/09/2014 Updated: 03/12/2016
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

expand.c in Exim prior to 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and execute arbitrary commands via a crafted lookup value.

Vulnerable Product Search on Vulmon Subscribe to Product

exim exim 4.77

exim exim 4.76

exim exim 4.69

exim exim 4.68

exim exim 4.61

exim exim 4.60

exim exim 4.42

exim exim 4.41

exim exim 4.24

exim exim 4.23

exim exim 4.10

exim exim 4.05

exim exim 4.75

exim exim 4.74

exim exim 4.67

exim exim 4.66

exim exim 4.54

exim exim 4.53

exim exim 4.40

exim exim 4.34

exim exim 4.22

exim exim 4.21

exim exim 4.04

exim exim 4.03

exim exim 4.02

exim exim

exim exim 4.73

exim exim 4.72

exim exim 4.65

exim exim 4.64

exim exim 4.52

exim exim 4.51

exim exim 4.50

exim exim 4.33

exim exim 4.32

exim exim 4.20

exim exim 4.14

exim exim 4.01

exim exim 4.00

exim exim 4.82

exim exim 4.80.1

exim exim 4.80

exim exim 4.71

exim exim 4.70

exim exim 4.63

exim exim 4.62

exim exim 4.44

exim exim 4.43

exim exim 4.31

exim exim 4.30

exim exim 4.12

exim exim 4.11

Vendor Advisories

Several security issues were fixed in Exim ...
expandc in Exim before 483 expands mathematical comparisons twice, which allows local users to gain privileges and execute arbitrary commands via a crafted lookup value ...