Courier sqwebmail before 0.40.0 does not quickly drop privileges after startup in certain cases, which could allow local users to read arbitrary files.
Link | Tags |
---|---|
http://www.iss.net/security_center/static/10643.php | vdb entry vendor advisory |
http://www.securityfocus.com/bid/6189 | vdb entry |
http://www.debian.org/security/2002/dsa-197 | patch vendor advisory |
http://marc.info/?l=bugtraq&m=103794021013436&w=2 | mailing list |