A UNIX Symbolic Link (Symlink) Following vulnerability in logrotate config in the exim package allowed privilege escalation from mail user/group to root.This issue affects Tumbleweed: from ? before 4.98.2-lp156.248.1.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-53881 |
|
History
Fri, 03 Oct 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Exim
Exim exim Opensuse Opensuse tumbleweed |
|
| Vendors & Products |
Exim
Exim exim Opensuse Opensuse tumbleweed |
Thu, 02 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 02 Oct 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A UNIX Symbolic Link (Symlink) Following vulnerability in logrotate config in the exim package allowed privilege escalation from mail user/group to root.This issue affects Tumbleweed: from ? before 4.98.2-lp156.248.1. | |
| Title | SUSE-specific logrotate configuration allows escalation from mail user/group to root | |
| Weaknesses | CWE-61 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: suse
Published: 2025-10-02T13:51:56.848Z
Updated: 2025-10-02T17:38:57.426Z
Reserved: 2025-07-11T10:53:52.681Z
Link: CVE-2025-53881
Updated: 2025-10-02T17:15:17.373Z
Status : Awaiting Analysis
Published: 2025-10-02T14:15:45.010
Modified: 2025-10-02T19:11:46.753
Link: CVE-2025-53881
No data.