Summary: | <mail-mta/nullmailer-1.11-r2 : world readable /etc/nullmailer/remotes (CVE-2013-4223) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | redneb <redneb> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | jlec, net-mail+disabled, robbat2 |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B3 [noglsa] | ||
Package list: | Runtime testing required: | --- |
Description
redneb
2013-08-09 14:15:50 UTC
This becomes a security bug from now, thanks for the report InCVS. Arches, please stabilize nullmailer-1.11-r2. Target keywords: amd64 ppc x86 amd64 stable ppc stable x86 stable Thanks for your work GLSA vote: no +*nullmailer-1.13-r2 (25 Sep 2013) + + 25 Sep 2013; Justin Lecher <jlec@gentoo.org> -nullmailer-1.11.ebuild, + -nullmailer-1.11-r1.ebuild, nullmailer-1.11-r2.ebuild, + nullmailer-1.11-r3.ebuild, -nullmailer-1.13.ebuild, + -nullmailer-1.13-r1.ebuild, +nullmailer-1.13-r2.ebuild, + +files/init.d-nullmailer-r3: + Drop old vulnerable versions, #480376; respect AR, #480394; make paludis + happy, #462846 thanks Thomas Witt for the patch; fix broken openrc + initscript, #480354 + Removed all versions in question. GLSA vote: no. Closing noglsa. |