Jump to content

Advisories MDVSA-2010:038: maildrop


paul
 Share

Recommended Posts

A vulnerability have been discovered and corrected in maildrop:

 

main.C in maildrop 2.3.0 and earlier, when run by root with the -d

option, uses the gid of root for execution of the .mailfilter file in

a user's home directory, which allows local users to gain privileges

via a crafted file (CVE-2010-0301).

 

The updated packages have been patched to correct this issue.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...