Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 600097 - (CVE-2010-2024) CVE-2010-2024 exim: race condition when MBX locking is enabled
CVE-2010-2024 exim: race condition when MBX locking is enabled
Status: CLOSED WONTFIX
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
public=20100603,reported=20100603,sou...
: Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2010-06-03 18:51 EDT by Vincent Danen
Modified: 2016-11-08 10:51 EST (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-07-29 10:44:43 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Vincent Danen 2010-06-03 18:51:27 EDT
Dan Rosenberg reported that when MBX locking is enabled in exim, local users could exploit a race condition to change permissions of other non-root users' files.  This could lead to a denial of service, to create new files owned by other users in unauthorized locations, or to possibly escalate privileges.

Further information is available from the upstream bug report [1] and this has
been fixed upstream in exim 4.72 [2].

[1] http://bugs.exim.org/show_bug.cgi?id=989
[2] http://vcs.exim.org/viewvc/exim/exim-src/src/transports/appendfile.c?r1=1.25&r2=1.26

While exim is built to support the MBX format, it is not the default for local mail delivery (Unix mailbox support is the default).  This will only affect users that use the "mbx_format" option in the appendfile transport.
Comment 1 Vincent Danen 2010-06-03 19:09:40 EDT
Statement:

The Red Hat Security Response Team has rated this issue as having low security impact.  While support for the MBX mailbox format is compiled into Exim, it is not used by default.  MBX mailboxes are only useful when used with UW-IMAP or the Pine mail client, neither of which are provided with Red Hat Enterprise Linux.  If the MBX format is used, this issue can be worked around by specifying "use_fcntl_lock" rather than "use_mbx_lock".  We therefore have no plans to fix this flaw in Red Hat Enterprise Linux 4 or 5.
Comment 2 Fedora Update System 2010-06-03 19:51:59 EDT
exim-4.72-1.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/exim-4.72-1.fc12
Comment 3 Fedora Update System 2010-06-03 19:53:02 EDT
exim-4.72-1.fc13 has been submitted as an update for Fedora 13.
http://admin.fedoraproject.org/updates/exim-4.72-1.fc13
Comment 4 Fedora Update System 2010-06-08 15:33:31 EDT
exim-4.72-1.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 5 Fedora Update System 2010-06-08 15:39:42 EDT
exim-4.72-1.fc13 has been pushed to the Fedora 13 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.