LWN.net Logo

Courier sqwebmail: buffer overflow

Package(s):Courier sqwebmail CVE #(s):
Created:November 15, 2002 Updated:November 19, 2002
Description: A problem in the Courier sqwebmail package, a CGI program to grant authenticated access to local mailboxes, has been discovered. The program did not drop permissions fast enough upon startup under certain circumstances so a local shell user can execute the sqwebmail binary and manage to read an arbitrary file on the local filesystem.
Alerts:
Debian DSA-197-1 2002-11-15

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds