Debian DSA-791-1 : maildrop - missing privilege release

critical Nessus Plugin ID 19561

Synopsis

The remote Debian host is missing a security-related update.

Description

Max Vozeler discovered that the lockmail program from maildrop, a simple mail delivery agent with filtering abilities, does not drop group privileges before executing commands given on the commandline, allowing an attacker to execute arbitrary commands with privileges of the group mail.

Solution

Upgrade the maildrop package.

The old stable distribution (woody) is not affected by this problem.

For the stable distribution (sarge) this problem has been fixed in version 1.5.3-1.1sarge1.

See Also

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=325135

http://www.debian.org/security/2005/dsa-791

Plugin Details

Severity: Critical

ID: 19561

File Name: debian_DSA-791.nasl

Version: 1.18

Type: local

Agent: unix

Published: 9/6/2005

Updated: 1/4/2021

Supported Sensors: Agentless Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:maildrop, cpe:/o:debian:debian_linux:3.1

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Patch Publication Date: 8/30/2005

Vulnerability Publication Date: 8/30/2005

Reference Information

CVE: CVE-2005-2655

DSA: 791