Bug#606527: root upgrade vulnerability in exim4

2010-12-10 Thread David Woodhouse
> (although sadly I can't see how to get it to render in a fixed-width > font). http://bugs.exim.org/show_bug.cgi?id=1044 -- David WoodhouseOpen Source Technology Centre david.woodho...@intel.com Intel Corporation -- To UNSUBSCRIBE, e

Bug#606527: root upgrade vulnerability in exim4

2010-12-10 Thread Dominic Hargreaves
On Thu, Dec 09, 2010 at 11:23:19PM +0100, Konrad Rosenbaum wrote: > The /usr/sbin/exim4 executable can be abused to upgrade from Debian-exim to > root in case of another vulnerability in exim that creates a shell (there > currently seems to be one). > > The exim config allows constructs like ${r

Bug#606527: root upgrade vulnerability in exim4

2010-12-10 Thread Marc Haber
severity #606527 grave tags #606527 confirmed security lenny squeeze thanks -- - Marc Haber | "I don't trust Computers. They | Mailadresse im Header Mannheim, Germany | lose things."Winona Ryder | Fon: *49 6

Processed: Re: Bug#606527: root upgrade vulnerability in exim4

2010-12-10 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity #606527 grave Bug #606527 [exim4] root upgrade vulnerability in exim4 Severity set to 'grave' from 'normal' > tags #606527 confirmed security lenny squeeze Bug #606527 [exim4] root upgrade vulnerability in exim4 Added tag(s) squeeze, con