Gentoo Archives: gentoo-announce

From: Sune Kloppenborg Jeppesen <jaervosz@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200505-17 ] Qpopper: Multiple Vulnerabilities
Date: Mon, 23 May 2005 19:48:09
Message-Id: 200505232148.11052.jaervosz@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200505-17
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Qpopper: Multiple Vulnerabilities
9 Date: May 23, 2005
10 Bugs: #90622
11 ID: 200505-17
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Qpopper contains two vulnerabilities allowing an attacker to overwrite
19 arbitrary files and create files with insecure permissions.
20
21 Background
22 ==========
23
24 Qpopper is a widely used server for the POP3 protocol.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 net-mail/qpopper < 4.0.5-r3 >= 4.0.5-r3
33
34 Description
35 ===========
36
37 Jens Steube discovered that Qpopper doesn't drop privileges to process
38 local files from normal users (CAN-2005-1151). The upstream developers
39 discovered that Qpopper can be forced to create group or world
40 writeable files (CAN-2005-1152).
41
42 Impact
43 ======
44
45 A malicious local attacker could exploit Qpopper to overwrite arbitrary
46 files as root or create new files which are group or world writeable.
47
48 Workaround
49 ==========
50
51 There is no known workaround at this time.
52
53 Resolution
54 ==========
55
56 All Qpopper users should upgrade to the latest available version:
57
58 # emerge --sync
59 # emerge --ask --oneshot --verbose ">=net-mail/qpopper-4.0.5-r3"
60
61 References
62 ==========
63
64 [ 1 ] CAN-2005-1151
65 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1151
66 [ 2 ] CAN-2005-1152
67 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1152
68
69 Availability
70 ============
71
72 This GLSA and any updates to it are available for viewing at
73 the Gentoo Security Website:
74
75 http://security.gentoo.org/glsa/glsa-200505-17.xml
76
77 Concerns?
78 =========
79
80 Security is a primary focus of Gentoo Linux and ensuring the
81 confidentiality and security of our users machines is of utmost
82 importance to us. Any security concerns should be addressed to
83 security@g.o or alternatively, you may file a bug at
84 http://bugs.gentoo.org.
85
86 License
87 =======
88
89 Copyright 2005 Gentoo Foundation, Inc; referenced text
90 belongs to its owner(s).
91
92 The contents of this document are licensed under the
93 Creative Commons - Attribution / Share Alike license.
94
95 http://creativecommons.org/licenses/by-sa/2.0