Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAMB8f9OFWiz8YGC6aE=ytRP3u+P_sy4oMG1Bz_PxQuLNC9fjcw@mail.gmail.com>
Date: Fri, 9 Aug 2013 15:35:02 -0400
From: Evan Teitelman <teitelmanevan@...il.com>
To: oss-security@...ts.openwall.com
Cc: ago@...too.org
Subject: Re: CVE request: nullmailer world readable /etc/nullmailer/remotes

On Fri, Aug 9, 2013 at 1:15 PM, Agostino Sarubbo <ago@...too.org> wrote:
> Hello,
>
> On Gentoo, the file /etc/nullmailer/remotes is installed with wrong
> permissions:
>
> ~ # ls -la /etc/nullmailer/remotes
> -rw-r--r-- 1 root root 971 Aug  9 18:58 /etc/nullmailer/remotes
>
> Nullmailer-1.11-r2 contains the fix, all prior versions are affected.
>
> Please assign a CVE.
> --
> Agostino Sarubbo
> Gentoo Linux Developer

Here is a link to the bug listing in the Gentoo issue tracker:
https://bugs.gentoo.org/show_bug.cgi?id=480376

And the fixed build code:
http://sources.gentoo.org/cgi-bin/viewvc.cgi/gentoo-x86/mail-mta/nullmailer/nullmailer-1.11-r2.ebuild

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.