Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 91465 - maildrop insecure file & directory permissions : informations leak
Summary: maildrop insecure file & directory permissions : informations leak
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A4 [noglsa] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2005-05-04 11:40 UTC by eromang
Modified: 2005-05-12 05:48 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description eromang 2005-05-04 11:40:52 UTC
Hello,

maildrop is used for mail delivery or filtering.

The /etc/maildrop/ directory containt the configuration file :

eric maildrop # ls -la
total 14
drwxr-xr-x   2 root root 1024 May  4 19:50 .
drwxr-xr-x  80 root root 4096 May  4 19:50 ..
-rw-r--r--   1 root root 4549 May  4 19:50 maildropldap.cf
-rw-r--r--   1 root root 3163 May  4 19:50 maildropmysql.cf

This files are world readable, a malicious local user could obtain senstive informations.

Reproducible: Always
Steps to Reproduce:
1.
2.
3.

Actual Results:  
This files are world readable.

Expected Results:  
This files should not be world readable
Comment 1 Fernando J. Pereda (RETIRED) gentoo-dev 2005-05-04 12:42:40 UTC
Fixed in CVS, thanks (is 1.7.0-r3)

Cheers,
Ferdy
Comment 2 Fernando J. Pereda (RETIRED) gentoo-dev 2005-05-04 12:55:39 UTC
Shouldn't have resolved that... im going to push 1.8.0 series as stable to fix this so we can remove the old ebuilds.

BTW, sorry for messing with security bugs, didn't notice the first time.

Cheers,
Ferdy
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-05-04 23:09:52 UTC
Arches please mark maildrop-1.8.0-r3 stable.
Comment 4 Bryan Østergaard (RETIRED) gentoo-dev 2005-05-05 01:25:38 UTC
Alpha stable.
Comment 5 Jeffrey Forman (RETIRED) gentoo-dev 2005-05-05 05:18:01 UTC
Looks good on Sparc, but I'm not bumping it until I get the nod from Weeve/Gustavoz

napavalley portage # cd /etc/maildrop
napavalley maildrop # ls -l
total 0
-rw-r-----  1 root root 0 May  5 08:16 maildropmysql.cf
Comment 6 Jeffrey Forman (RETIRED) gentoo-dev 2005-05-05 07:36:44 UTC
Stable on sparc.
Comment 7 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-05-11 07:24:25 UTC
Oops slipped under my radar. This one is ready for GLSA decision. I tend to vote NO.
Comment 8 Thierry Carrez (RETIRED) gentoo-dev 2005-05-12 05:48:42 UTC
I agree with NO. Specific subconfig files containing passwords should/could be restricted post-config on machines with local hostiles...

Closing.