1 |
-----BEGIN PGP SIGNED MESSAGE----- |
2 |
Hash: SHA1 |
3 |
|
4 |
- - -------------------------------------------------------------------- |
5 |
GENTOO LINUX SECURITY ANNOUNCEMENT 200211-005 |
6 |
- - -------------------------------------------------------------------- |
7 |
|
8 |
PACKAGE : courier |
9 |
SUMMARY : buffer overflow |
10 |
DATE : 2002-11-19 13:11 UTC |
11 |
EXPLOIT : local |
12 |
|
13 |
- - -------------------------------------------------------------------- |
14 |
|
15 |
- From Debian Security Advisory DSA 197-1 : |
16 |
|
17 |
A problem in the Courier sqwebmail package, a CGI program to grant |
18 |
authenticated access to local mailboxes, has been discovered. The |
19 |
program did not drop permissions fast enough upon startup under |
20 |
certain circumstances so a local shell user can execute the sqwebmail |
21 |
binary and manage to read an arbitrary file on the local filesystem. |
22 |
|
23 |
SOLUTION |
24 |
|
25 |
It is recommended that all Gentoo Linux users who are running |
26 |
net-mail/courier-0.40.0.20021026 and earlier update their systems as |
27 |
follows: |
28 |
|
29 |
emerge rsync |
30 |
emerge courier |
31 |
emerge clean |
32 |
|
33 |
- - -------------------------------------------------------------------- |
34 |
aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz |
35 |
- - -------------------------------------------------------------------- |
36 |
-----BEGIN PGP SIGNATURE----- |
37 |
Version: GnuPG v1.0.7 (GNU/Linux) |
38 |
|
39 |
iD8DBQE92kCafT7nyhUpoZMRAlpYAKC4NgU/HGbbQoveI+uBAQi81TU2LACfVDLE |
40 |
vgIc8zIzeNAZmQxM4XpCTog= |
41 |
=YIvq |
42 |
-----END PGP SIGNATURE----- |