From aliz@gentoo.org Wed Nov 20 19:41:01 2002 From: Daniel Ahlberg To: full-disclosure@lists.netsys.com Date: Tue, 19 Nov 2002 14:46:06 +0100 Subject: [Full-Disclosure] GLSA: courier -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - -------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200211-005 - - -------------------------------------------------------------------- PACKAGE : courier SUMMARY : buffer overflow DATE    : 2002-11-19 13:11 UTC EXPLOIT : local - - -------------------------------------------------------------------- - From Debian Security Advisory DSA 197-1 : A problem in the Courier sqwebmail package, a CGI program to grant authenticated access to local mailboxes, has been discovered. The program did not drop permissions fast enough upon startup under certain circumstances so a local shell user can execute the sqwebmail binary and manage to read an arbitrary file on the local filesystem. SOLUTION It is recommended that all Gentoo Linux users who are running net-mail/courier-0.40.0.20021026 and earlier update their systems as follows: emerge rsync emerge courier emerge clean - - -------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at www.gentoo.org/~aliz - - -------------------------------------------------------------------- -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQE92kCafT7nyhUpoZMRAlpYAKC4NgU/HGbbQoveI+uBAQi81TU2LACfVDLE vgIc8zIzeNAZmQxM4XpCTog= =YIvq -----END PGP SIGNATURE----- _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html