|
Message-ID: <CAMB8f9OFWiz8YGC6aE=ytRP3u+P_sy4oMG1Bz_PxQuLNC9fjcw@mail.gmail.com> Date: Fri, 9 Aug 2013 15:35:02 -0400 From: Evan Teitelman <teitelmanevan@...il.com> To: oss-security@...ts.openwall.com Cc: ago@...too.org Subject: Re: CVE request: nullmailer world readable /etc/nullmailer/remotes On Fri, Aug 9, 2013 at 1:15 PM, Agostino Sarubbo <ago@...too.org> wrote: > Hello, > > On Gentoo, the file /etc/nullmailer/remotes is installed with wrong > permissions: > > ~ # ls -la /etc/nullmailer/remotes > -rw-r--r-- 1 root root 971 Aug 9 18:58 /etc/nullmailer/remotes > > Nullmailer-1.11-r2 contains the fix, all prior versions are affected. > > Please assign a CVE. > -- > Agostino Sarubbo > Gentoo Linux Developer Here is a link to the bug listing in the Gentoo issue tracker: https://bugs.gentoo.org/show_bug.cgi?id=480376 And the fixed build code: http://sources.gentoo.org/cgi-bin/viewvc.cgi/gentoo-x86/mail-mta/nullmailer/nullmailer-1.11-r2.ebuild
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.