The-Z-Labs / linux-exploit-suggester

Linux privilege escalation auditing tool
GNU General Public License v3.0
5.54k stars 1.09k forks source link

Add GNU Mailutils maidag url local root (CVE-2019-18862) #69

Closed bcoles closed 4 years ago

bcoles commented 4 years ago

Exploitable only when /usr/local/sbin/maidag is set-uid root.

Mailutils, when installed from software package repositories, usually does not set maidag set-uid root.

The issue was patched by removing maidag.