Debians sikkerhedsbulletin
DSA-791-1 maildrop -- manglende frigivelse af rettigheder
- Rapporteret den:
- 30. aug 2005
- Berørte pakker:
- maildrop
- Sårbar:
- Ja
- Referencer i sikkerhedsdatabaser:
- I Debians fejlsporingssystem: Fejl 325135.
I Mitres CVE-ordbog: CVE-2005-2655. - Yderligere oplysninger:
-
Max Vozeler har opdaget at lockmail-programmet fra maildrop, et simpelt program til aflevering af post med filtereringsfunktionalitet, ikke smider grupperettigheder væk før udførelsen af kommandoer angivet på kommandolinjen, hvilket gjorde det muligt for en angriber at udføre vilkårlige kommandoer med rettighederne hørende til gruppen mail.
Den gamle stabile distribution (woody) er ikke påvirket af dette problem.
I den stabile distribution (sarge) er dette problem rettet i version 1.5.3-1.1sarge1.
I den ustabile distribution (sid) er dette problem rettet i version 1.5.3-2.
Vi anbefaler at du opgraderer din maildrop-pakke.
- Rettet i:
-
Debian GNU/Linux 3.1 (sarge)
- Kildekode:
- http://security.debian.org/pool/updates/main/m/maildrop/maildrop_1.5.3-1.1sarge1.dsc
- http://security.debian.org/pool/updates/main/m/maildrop/maildrop_1.5.3-1.1sarge1.diff.gz
- http://security.debian.org/pool/updates/main/m/maildrop/maildrop_1.5.3.orig.tar.gz
- http://security.debian.org/pool/updates/main/m/maildrop/maildrop_1.5.3-1.1sarge1.diff.gz
- Alpha:
- http://security.debian.org/pool/updates/main/m/maildrop/maildrop_1.5.3-1.1sarge1_alpha.deb
- AMD64:
- http://security.debian.org/pool/updates/main/m/maildrop/maildrop_1.5.3-1.1sarge1_amd64.deb
- ARM:
- http://security.debian.org/pool/updates/main/m/maildrop/maildrop_1.5.3-1.1sarge1_arm.deb
- Intel IA-32:
- http://security.debian.org/pool/updates/main/m/maildrop/maildrop_1.5.3-1.1sarge1_i386.deb
- Intel IA-64:
- http://security.debian.org/pool/updates/main/m/maildrop/maildrop_1.5.3-1.1sarge1_ia64.deb
- HPPA:
- http://security.debian.org/pool/updates/main/m/maildrop/maildrop_1.5.3-1.1sarge1_hppa.deb
- Motorola 680x0:
- http://security.debian.org/pool/updates/main/m/maildrop/maildrop_1.5.3-1.1sarge1_m68k.deb
- Big endian MIPS:
- http://security.debian.org/pool/updates/main/m/maildrop/maildrop_1.5.3-1.1sarge1_mips.deb
- Little endian MIPS:
- http://security.debian.org/pool/updates/main/m/maildrop/maildrop_1.5.3-1.1sarge1_mipsel.deb
- PowerPC:
- http://security.debian.org/pool/updates/main/m/maildrop/maildrop_1.5.3-1.1sarge1_powerpc.deb
- IBM S/390:
- http://security.debian.org/pool/updates/main/m/maildrop/maildrop_1.5.3-1.1sarge1_s390.deb
- Sun Sparc:
- http://security.debian.org/pool/updates/main/m/maildrop/maildrop_1.5.3-1.1sarge1_sparc.deb
MD5-kontrolsummer for de listede filer findes i den originale sikkerhedsbulletin.