| |||||||||||||
| Test Kennung: | 1.3.6.1.4.1.25623.1.0.800292 |
| Kategorie: | Privilege escalation |
| Titel: | Maildrop Privilege Escalation Vulnerability |
| Zusammenfassung: | Check for the version of Maildrop |
| Beschreibung: | Overview: This host is installed Maildrop and is prone to Privilege Escalation vulnerability Vulnerability Insight: The flaw is due to the error in the 'maildrop/main.C', when run by root with the '-d' option, uses the gid of root for execution of the mailfilter file in a user's home directory. Impact: Successful exploitation will allow local users to gain elevated privileges. Impact Level: Application. Affected Software : Maildrop version 2.3.0 and prior. Fix: Upgrade to Maildrop version 2.4.0 For updates refer to http://sourceforge.net/projects/courier/files/ References: http://secunia.com/advisories/38367 http://xforce.iss.net/xforce/xfdb/55980 http://securitytracker.com/alerts/2010/Jan/1023515.html |
| Querverweis: |
Common Vulnerability Exposure (CVE) ID: CVE-2010-0301 http://marc.info/?l=oss-security&m=126462927918840&w=2 http://marc.info/?l=oss-security&m=126468324913920&w=2 http://marc.info/?l=oss-security&m=126468551017070&w=2 http://marc.info/?l=oss-security&m=126468618017829&w=2 Debian Security Information: DSA-1981 (Google Search) http://www.debian.org/security/2010/dsa-1981 http://securitytracker.com/id?1023515 http://secunia.com/advisories/38367 http://secunia.com/advisories/38374 XForce ISS Database: maildrop-group-priv-escalation(55980) http://xforce.iss.net/xforce/xfdb/55980 |
| Copyright | Copyright (C) 2010 Greenbone Networks GmbH |
| Dies ist nur einer von 32582 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |
|