vendor:
Exim with Dovecot LDA and Common Example Documentation
by:
Redteam Pentesting
7,5
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Exim with Dovecot LDA and Common Example Documentation
Affected Version From: Example Configuration in Dovecot Wiki since 2009-10-23
Affected Version To: Example Configuration in Dovecot Wiki since 2009-10-23
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
Advisory: Exim with Dovecot: Typical Misconfiguration Leads to Remote Command Execution
During a penetration test a typical misconfiguration was found in the way Dovecot is used as a local delivery agent by Exim. A common use case for the Dovecot IMAP and POP3 server is the use of Dovecot as a local delivery agent for Exim. The Dovecot documentation contains an example using a dangerous configuration option for Exim, which leads to a remote command execution vulnerability in Exim.
Mitigation:
The vulnerable configuration option should be removed from the Exim configuration.