| Summary: | net-mail/dovecot-2.0.16 dovecot-lda should no be suid | ||
|---|---|---|---|
| Product: | Gentoo Linux | Reporter: | Francesco Riosa <vivo75> |
| Component: | [OLD] Server | Assignee: | Eray Aslan <eras> |
| Status: | RESOLVED INVALID | ||
| Severity: | normal | CC: | net-mail+disabled |
| Priority: | Normal | ||
| Version: | unspecified | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Package list: | Runtime testing required: | --- | |
forgot to mention, I'm quite sure this changed with 2.0.16, breaking existing installations. Turn off suid USE flag if you do not want a suid dovecot-lda. sorry for the noise, I've totally missed the use flag |
/usr/libexec/dovecot/deliver which is a symlynk to /usr/libexec/dovecot/dovecot-lda is suid. This conflict with the need of postfix (for example) to run it under it's own user, follow a master.cf exerpt: dovecot-lda unix - n n - - pipe flags=DRhu user=vmail:vmail argv=/usr/libexec/dovecot/deliver -f ${sender} -d ${user}@${domain} suggestion: Control the flags of this executable with an USE flag.