CVE-2010-2023

Publication date

2010-06-07 14:00:00

Family

mitre

State

PUBLISHED

Description

transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by creating a hard link to another users file.