|Category:||FreeBSD Local Security Checks|
|Title:||FreeBSD Ports: qpopper|
|Summary:||FreeBSD Ports: qpopper|
|Description:||The remote host is missing an update to the system|
as announced in the referenced advisory.
The following package is affected: qpopper
qpopper 4.0.5 and earlier does not properly drop privileges before
processing certain user-supplied files, which allows local users to
overwrite or create arbitrary files as root.
popauth.c in qpopper 4.0.5 and earlier does not properly set the
umask, which may cause qpopper to create files with group or
Update your system with the appropriate patches or
Common Vulnerability Exposure (CVE) ID: CVE-2005-1151|
Debian Security Information: DSA-728 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2005-1152
|Copyright||Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com|
|This is only one of 40605 vulnerability tests in our test suite. Find out more about running a complete security audit.|
To run a free test of this vulnerability against your system, register below.