<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>91465</bug_id>
          
          <creation_ts>2005-05-04 11:40 0000</creation_ts>
          <short_desc>maildrop insecure file &amp; directory permissions : informations leak</short_desc>
          <delta_ts>2005-05-12 05:48:42 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>A4 [noglsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>eromang@zataz.net</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>net-mail@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>eromang@zataz.net</who>
            <bug_when>2005-05-04 11:40:52 0000</bug_when>
            <thetext>Hello,

maildrop is used for mail delivery or filtering.

The /etc/maildrop/ directory containt the configuration file :

eric maildrop # ls -la
total 14
drwxr-xr-x   2 root root 1024 May  4 19:50 .
drwxr-xr-x  80 root root 4096 May  4 19:50 ..
-rw-r--r--   1 root root 4549 May  4 19:50 maildropldap.cf
-rw-r--r--   1 root root 3163 May  4 19:50 maildropmysql.cf

This files are world readable, a malicious local user could obtain senstive informations.

Reproducible: Always
Steps to Reproduce:
1.
2.
3.

Actual Results:  
This files are world readable.

Expected Results:  
This files should not be world readable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ferdy@gentoo.org</who>
            <bug_when>2005-05-04 12:42:40 0000</bug_when>
            <thetext>Fixed in CVS, thanks (is 1.7.0-r3)

Cheers,
Ferdy</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ferdy@gentoo.org</who>
            <bug_when>2005-05-04 12:55:39 0000</bug_when>
            <thetext>Shouldn&apos;t have resolved that... im going to push 1.8.0 series as stable to fix this so we can remove the old ebuilds.

BTW, sorry for messing with security bugs, didn&apos;t notice the first time.

Cheers,
Ferdy</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-05-04 23:09:52 0000</bug_when>
            <thetext>Arches please mark maildrop-1.8.0-r3 stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2005-05-05 01:25:38 0000</bug_when>
            <thetext>Alpha stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jforman@gentoo.org</who>
            <bug_when>2005-05-05 05:18:01 0000</bug_when>
            <thetext>Looks good on Sparc, but I&apos;m not bumping it until I get the nod from Weeve/Gustavoz

napavalley portage # cd /etc/maildrop
napavalley maildrop # ls -l
total 0
-rw-r-----  1 root root 0 May  5 08:16 maildropmysql.cf
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jforman@gentoo.org</who>
            <bug_when>2005-05-05 07:36:44 0000</bug_when>
            <thetext>Stable on sparc.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-05-11 07:24:25 0000</bug_when>
            <thetext>Oops slipped under my radar. This one is ready for GLSA decision. I tend to vote NO.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-05-12 05:48:42 0000</bug_when>
            <thetext>I agree with NO. Specific subconfig files containing passwords should/could be restricted post-config on machines with local hostiles...

Closing.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>