PublicDate: 2006-03-19 01:02:00 UTC Candidate: CVE-2006-1251 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1251 Description: Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field that contains a filename separated by whitespace, which is not quoted when greylistclean.cron provides the argument to the rm command. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: #sid_PKG: #dapper_PKG: #edgy_PKG: #feisty_PKG: #devel_PKG: dapper_sa-exim: ignored (reached end-of-life) edgy_sa-exim: released (4.2.1-1) feisty_sa-exim: released (4.2.1-1) gutsy_sa-exim: released (4.2.1-1) hardy_sa-exim: released (4.2.1-1) intrepid_sa-exim: released (4.2.1-1) jaunty_sa-exim: released (4.2.1-1) karmic_sa-exim: released (4.2.1-1) devel_sa-exim: released (4.2.1-1) upstream_sa-exim: released (4.2.1)