[8427] in bugtraq

home help back first fref pref prev next nref lref last post

Possible mail spool problem

daemon@ATHENA.MIT.EDU (signal)
Thu Nov 5 15:21:15 1998

Date: 	Wed, 4 Nov 1998 20:06:32 -0600
Reply-To: signal <soren@PANGEA.CA>
From: signal <soren@PANGEA.CA>
To: BUGTRAQ@NETSPACE.ORG

Following installation of suse 5.1, the setup software sets the mail spool
directory world writable, which has a potential of causing some security
problems.  although I have checked alot of possible forms of exploiting
this, there is probably some I have missed.  removing the o+w bit from the
directory will surely solve the problems.

                                                signal
                                                <soren@PANGEA.CA>

home help back first fref pref prev next nref lref last post