Package: dovecot-imapd
Severity: critical
Tags: security
Justification: root security hole

I believe all versions of Dovecot in Debian are concerned by this warning : 
http://dovecot.org/list/dovecot/2008-March/029196.html
On fairly standard Debian installations (Etch & Lenny) with mail delivered in 
/var/mail I was able to read other users' mboxes through a symlink in ~/Mail.

-- System Information:
Debian Release: lenny/sid
  APT prefers testing
  APT policy: (900, 'testing'), (900, 'stable'), (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.24-1-686 (SMP w/2 CPU cores)
Locale: [EMAIL PROTECTED], [EMAIL PROTECTED] (charmap=ISO-8859-15)
Shell: /bin/sh linked to /bin/bash

Versions of packages dovecot-imapd depends on:
pn  dovecot-common                <none>     (no description available)
ii  libc6                         2.7-6      GNU C Library: Shared libraries
ii  libssl0.9.8                   0.9.8g-4   SSL shared libraries

dovecot-imapd recommends no packages.



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to