Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Gentoo: GLSA 202311-01 Critical: Maildrop Remote Code Execution

gentoo
Calendar Grey September 6, 2010
Dist Gentoo Esm H88
The Debian security advisory DSA 2021-05 details a critical vulnerability in Dovecot, which permits unauthorized access to sensitive user data.
Insecure permission handling in maildrop might allow local attackers to elevate their privileges.

Summary

Christoph Anton Mitterer reported that maildrop does not properly drop its privileges when run as root.

Resolution

All maildrop users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=mail-filter/maildrop-2.4.2"

References

[ 1 ] CVE-2010-0301 https://www.cve.org/CVERecord?id=CVE-2010-0301

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201009-02
style>.gentoo_availability{display:block;}

Concerns

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

Severity
important
Lowest
Low
Medium
High
Critical

Severity: High
Title: Maildrop: privilege escalation
Date: September 06, 2010
Bugs: #308043
ID: 201009-02

Synopsis

Insecure permission handling in maildrop might allow local attackers to elevate their privileges.

Background

maildrop is the mail filter/mail delivery agent that is used by the Courier Mail Server.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 mail-filter/maildrop < 2.4.2 >= 2.4.2

Impact

===== A local attacker could create a specially crafted .mailfilter file, possibly leading to the execution of arbitrary commands with the "root" group privileges. NOTE: Successful exploitation requires that maildrop is run as root with the -d option.

Workaround

There is no known workaround at this time.

Related News

Your message here