vendor:
Mailutils
by:
Mike Gualtieri
7.8
CVSS
HIGH
Local Privilege Escalation
269
CWE
Product Name: Mailutils
Affected Version From: 2
Affected Version To: 3.7
Patch Exists: YES
Related CWE: CVE-2019-18862
CPE: a:gnu:mailutils
Platforms Tested: Gentoo
2019
GNU Mailutils 3.7 – Local Privilege Escalation
The --url parameter included in the GNU Mailutils maidag utility can be abused to write to arbitrary files on the host operating system, leading to local privilege escalation. By default, maidag is set to execute with setuid root permissions.
Mitigation:
Update to a patched version of GNU Mailutils.