Debian sSMTP 'ssmtp.conf' Insecure File Permissions Vulnerability
BID:60943
Info
Debian sSMTP 'ssmtp.conf' Insecure File Permissions Vulnerability
| Bugtraq ID: | 60943 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 03 2013 12:00AM |
| Updated: | Jul 03 2013 12:00AM |
| Credit: | mark cunningham |
| Vulnerable: |
Red Hat Fedora 17 |
| Not Vulnerable: | |
Discussion
Debian sSMTP 'ssmtp.conf' Insecure File Permissions Vulnerability
sSMTP is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue by gaining access to a world-readable configuration file and extracting sensitive information from it. Such information could aid in other attacks.
sSMTP 2.64-4 is vulnerable; other versions may also be affected.
sSMTP is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue by gaining access to a world-readable configuration file and extracting sensitive information from it. Such information could aid in other attacks.
sSMTP 2.64-4 is vulnerable; other versions may also be affected.
Exploit / POC
Debian sSMTP 'ssmtp.conf' Insecure File Permissions Vulnerability
Attackers can use readily available tools and standard commands to exploit this issue.
Attackers can use readily available tools and standard commands to exploit this issue.
Solution / Fix
Debian sSMTP 'ssmtp.conf' Insecure File Permissions Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Debian sSMTP 'ssmtp.conf' Insecure File Permissions Vulnerability
References:
References: