Courier SqWebMail Privilege Dropping Bug Lets Local Users View Files on the System
Categorie: Vulnerability Posted: 2002-11-18 by ReCall Views: 356 Source: Click here
Current Rating: Not rated
Details
Description: A vulnerability was reported in Courier SqWebMail. A local user could view files on the system with elevated privileges.
It is reported that the software does not drop root permissions fast enough when starting up under certain circumstances, due to a flaw in 'sqwebmail.c'. A local user could exploit this to view arbitrary files on the system.
Impact: A local user could view files on the system with root privileges.
Solution: The vendor has released a fixed version (3.4.0.20021026), available at: