Bugtraq mailing list archives

Possible mail spool problem


From: soren () PANGEA CA (signal)
Date: Wed, 4 Nov 1998 20:06:32 -0600


Following installation of suse 5.1, the setup software sets the mail spool
directory world writable, which has a potential of causing some security
problems.  although I have checked alot of possible forms of exploiting
this, there is probably some I have missed.  removing the o+w bit from the
directory will surely solve the problems.

                                                signal
                                                <soren () PANGEA CA>



Current thread: