A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://bugzilla.suse.com/show_bug.cgi?id=984639 | third party advisory issue tracking exploit |
https://bugzilla.redhat.com/show_bug.cgi?id=1346055 | third party advisory issue tracking exploit |
http://lists.opensuse.org/opensuse-updates/2016-11/msg00096.html | third party advisory mailing list |