[8427] in bugtraq
Possible mail spool problem
daemon@ATHENA.MIT.EDU (signal)
Thu Nov 5 15:21:15 1998
Date: Wed, 4 Nov 1998 20:06:32 -0600
Reply-To: signal <soren@PANGEA.CA>
From: signal <soren@PANGEA.CA>
To: BUGTRAQ@NETSPACE.ORG
Following installation of suse 5.1, the setup software sets the mail spool
directory world writable, which has a potential of causing some security
problems. although I have checked alot of possible forms of exploiting
this, there is probably some I have missed. removing the o+w bit from the
directory will surely solve the problems.
signal
<soren@PANGEA.CA>