LWN.net Logo

ssmtp: world-readable password file

Package(s):ssmtp CVE #(s):
Created:July 4, 2013 Updated:July 10, 2013
Description:

From the Red Hat bugzilla entry:

In order to have ssmtp working for every user on the machine, the file /etc/ssmtp/ssmtp.conf must be readable by every user (others must at least have the read right to this file).

If an authentication smtp server is used (as gmail for example), the login and password appears in clear text in ssmtp.conf. This is obviously a security problem.

Alerts:
Fedora FEDORA-2013-10128 2013-07-04

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds