Author: Jeremy Harris Date: To: exim-users Subject: Re: [exim] Security release for CVE-2016-1531: 4.84.2, 4.85.2,
4.86.2, 4.87 RC5
On 09/03/16 17:07, Cyborg wrote: > The question is, who stops the attacker from loading a config he likes
> directly into exim WITH the new vars set ?
The config filename is compiled-in, or the filename carrying permitted
config file names is compiled-in. Also the config file must be owned
by root or a user that is compiled-in, and not world-writable.
See Chapter 6, first few paragraphs.
--
Cheers,
Jeremy