CyberRota Analysis
AI-GeneratedExim versions prior to 4.99.5 are vulnerable to a directory traversal attack that allows unauthorized access to files outside the designated spool area, potentially leading to privilege escalation. This vulnerability arises from improper handling of queue-name arguments, which could be exploited by attackers to manipulate file access. Organizations using affected Exim versions should prioritize patching to mitigate the risk of unauthorized access and privilege escalation.
Original NVD Description
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
Related CVEs
Other vulnerabilities affecting the same vendor(s)