Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: courier
Date: Tue, 19 Nov 2002 14:37:46
Message-Id: 20021119134605.633AD338DB@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200211-005
6 - - --------------------------------------------------------------------
7
8 PACKAGE : courier
9 SUMMARY : buffer overflow
10 DATE    : 2002-11-19 13:11 UTC
11 EXPLOIT : local
12
13 - - --------------------------------------------------------------------
14
15 - From Debian Security Advisory DSA 197-1 :
16
17 A problem in the Courier sqwebmail package, a CGI program to grant
18 authenticated access to local mailboxes, has been discovered. The
19 program did not drop permissions fast enough upon startup under
20 certain circumstances so a local shell user can execute the sqwebmail
21 binary and manage to read an arbitrary file on the local filesystem.
22
23 SOLUTION
24
25 It is recommended that all Gentoo Linux users who are running
26 net-mail/courier-0.40.0.20021026 and earlier update their systems as
27 follows:
28
29 emerge rsync
30 emerge courier
31 emerge clean
32
33 - - --------------------------------------------------------------------
34 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
35 - - --------------------------------------------------------------------
36 -----BEGIN PGP SIGNATURE-----
37 Version: GnuPG v1.0.7 (GNU/Linux)
38
39 iD8DBQE92kCafT7nyhUpoZMRAlpYAKC4NgU/HGbbQoveI+uBAQi81TU2LACfVDLE
40 vgIc8zIzeNAZmQxM4XpCTog=
41 =YIvq
42 -----END PGP SIGNATURE-----