SuSEConfig.postfix chroot File Ownership Vulnerability
BID:3637
Info
SuSEConfig.postfix chroot File Ownership Vulnerability
| Bugtraq ID: | 3637 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 05 2001 12:00AM |
| Updated: | Dec 05 2001 12:00AM |
| Credit: | Discovered by Matthias Andree <[email protected]>. |
| Vulnerable: |
S.u.S.E. SuSEConfig.postfix |
| Not Vulnerable: | |
Exploit / POC
SuSEConfig.postfix chroot File Ownership Vulnerability
No exploit code is required to take advantage of this issue.
No exploit code is required to take advantage of this issue.
Solution / Fix
SuSEConfig.postfix chroot File Ownership Vulnerability
Solution:
As a solution, Matthias Andree <[email protected]> has suggested changing the ownership of appropriate files to the root user, and applying a 755 or 644 permission mask to protect them from the postfix user account.
A modified SuSEConfig.postfix file has been made available by Matthias Andree, at:
http://mandree.home.pages.de/postfix/
Solution:
As a solution, Matthias Andree <[email protected]> has suggested changing the ownership of appropriate files to the root user, and applying a 755 or 644 permission mask to protect them from the postfix user account.
A modified SuSEConfig.postfix file has been made available by Matthias Andree, at:
http://mandree.home.pages.de/postfix/
References
SuSEConfig.postfix chroot File Ownership Vulnerability
References:
References:
- Postfix Homepage (Wietse Venema)
- S.u.S.E. Homepage (S.u.S.E.)