Your message dated Thu, 28 Jan 2010 19:47:56 +0000
with message-id <e1naalm-0001de...@ries.debian.org>
and subject line Bug#564601: fixed in maildrop 2.2.0-3.1
has caused the Debian Bug report #564601,
regarding possible problems when switching UID/GIDs in delivery mode when run 
as root
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
564601: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=564601
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: maildrop
Justification: user security hole
Severity: grave
Tags: security

Hi.

Not sure if this actually a hole or if I just misunderstand
something,... but:

In debian /usr/bin/maildrop ist installed:
-rwxr-sr-x 1 root mail 163k Nov  9 01:11 /usr/bin/maildrop

So I'd expect that the following invocation (as root!!):
# maildrop -d vmail
results in something like the following contents of /tmp/foo:
uid=115(vmail) gid=119(vmail) groups=119(vmail),119(vmail)
when ~vmail/.mailfilter is:
`id`

Right so far?
It does however result in:
uid=115(vmail) gid=0(root) groups=119(vmail),0(root)
which can be quite security critical as it now has root-group
privileges.


Cheers,
Chris.




--- End Message ---
--- Begin Message ---
Source: maildrop
Source-Version: 2.2.0-3.1

We believe that the bug you reported is fixed in the latest version of
maildrop, which is due to be installed in the Debian FTP archive:

maildrop_2.2.0-3.1.diff.gz
  to main/m/maildrop/maildrop_2.2.0-3.1.diff.gz
maildrop_2.2.0-3.1.dsc
  to main/m/maildrop/maildrop_2.2.0-3.1.dsc
maildrop_2.2.0-3.1_i386.deb
  to main/m/maildrop/maildrop_2.2.0-3.1_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 564...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Steffen Joeris <wh...@debian.org> (supplier of updated maildrop package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Thu, 28 Jan 2010 20:24:22 +0100
Source: maildrop
Binary: maildrop
Architecture: source i386
Version: 2.2.0-3.1
Distribution: unstable
Urgency: high
Maintainer: Josip Rodin <joy-packa...@debian.org>
Changed-By: Steffen Joeris <wh...@debian.org>
Description: 
 maildrop   - mail delivery agent with filtering abilities
Closes: 564601
Changes: 
 maildrop (2.2.0-3.1) unstable; urgency=high
 .
   * Non-maintainer upload by the security team
   * Fix privilege escalation via maildrop -d which grants root group
     privileges (Closes: #564601) Thanks to Sam Varshavchik
Checksums-Sha1: 
 f2ce686042c60a93c32608717735f02bc6d60dfa 1101 maildrop_2.2.0-3.1.dsc
 39a43fcaa2f4f3d79b7c0e2c09378950178a9361 631070 maildrop_2.2.0-3.1.diff.gz
 fba21c6a89d01aee9f8aa043bd42fa79020ed5c5 367904 maildrop_2.2.0-3.1_i386.deb
Checksums-Sha256: 
 d35722c442c34b391f41a95ff76837c2f81688e13c983a5845efad8581433f14 1101 
maildrop_2.2.0-3.1.dsc
 f56f279bb17182f0e5bf1b9cb2156f908da0bae1e3e0097341a7298e4c7e8bab 631070 
maildrop_2.2.0-3.1.diff.gz
 b15acf5062468abd9becca55e201c20ba3550b20956e3beb973a25d3099d3835 367904 
maildrop_2.2.0-3.1_i386.deb
Files: 
 5b0031829042677e03bbcab35211a7b3 1101 mail optional maildrop_2.2.0-3.1.dsc
 3db51f268a0209dfb9b28728c3189362 631070 mail optional 
maildrop_2.2.0-3.1.diff.gz
 f4c7f47026047b8c6e714c7eb8f325be 367904 mail optional 
maildrop_2.2.0-3.1_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkth5u8ACgkQ62zWxYk/rQcWtwCfetQFArCCjEiu04t6ULGWQ73g
WW4AnRywfp0YoVkl3M51vBMzIhGqx6mf
=j/Uv
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to