Maildrop: privilege escalation
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201009-02 / maildrop |
| Release Date |
September 06, 2010 |
| Latest Revision |
September 06, 2010: 01 |
| Impact |
high |
| Exploitable |
local |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| mail-filter/maildrop |
<
2.4.2 |
>=
2.4.2 |
All supported architectures
|
Related bugreports:
#308043
Synopsis
Insecure permission handling in maildrop might allow local attackers to
elevate their privileges.
2.
Impact Information
Background
maildrop is the mail filter/mail delivery agent that is used by the
Courier Mail Server.
Description
Christoph Anton Mitterer reported that maildrop does not properly drop
its privileges when run as root.
Impact
A local attacker could create a specially crafted .mailfilter file,
possibly leading to the execution of arbitrary commands with the "root"
group privileges. NOTE: Successful exploitation requires that maildrop
is run as root with the -d option.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All maildrop users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=mail-filter/maildrop-2.4.2"
|
4.
References
|