vendor:
exim
by:
Dark Eagle
N/A
CVSS
N/A
Unknown
Unknown
CWE
Product Name: exim
Affected Version From: Unknown
Affected Version To: 4.42
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested:
2005
Local Lame R00T sploit for exim <= 4.42
This is a local exploit script written in bash that targets exim versions <= 4.42. It includes a C code snippet that is used to get the address of a given environment variable. The script then compiles the C code and copies it to /usr/bin. It then changes directory to /usr/exim/bin and executes the exim binary with a crafted argument that triggers the exploit.
Mitigation:
Unknown