CVE-2006-1251

Publication date 19 March 2006

Last updated 17 July 2025


Ubuntu priority

Description

Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field that contains a filename separated by whitespace, which is not quoted when greylistclean.cron provides the argument to the rm command.

Status

Package Ubuntu Release Status
sa-exim 9.10 karmic
Fixed 4.2.1-1
9.04 jaunty
Fixed 4.2.1-1
8.10 intrepid
Fixed 4.2.1-1
8.04 LTS hardy
Fixed 4.2.1-1
7.10 gutsy
Fixed 4.2.1-1
7.04 feisty
Fixed 4.2.1-1
6.10 edgy
Fixed 4.2.1-1
6.06 LTS dapper Ignored end of life


Access our resources on patching vulnerabilities