From 090dbb7b77d15ec9d072089f51c17e73d6e22f59 Mon Sep 17 00:00:00 2001 From: Rong-En Fan Date: Sun, 6 Apr 2008 08:50:37 +0000 Subject: - Add entry for mail/postfix-policyd-weight PR: ports/122194 Reviewed by: ports-security (miwi) --- security/vuxml/vuln.xml | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) (limited to 'security') diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index f66d2750e7a3..289ea8b79a10 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -34,6 +34,34 @@ Note: Please add new entries to the beginning of this file. --> + + postfix-policyd-weight -- working directory symlink vulnerability + + + postfix-policyd-weight + 0.1.14.17 + + + + +

postfix-policyd-weight does not check for symlink for its working + directory. If the working directory is not already setup by the + super root, an unprivileged user can link it to another directories + in the system. This results in ownership/permission changes on the + target directory.

+ +
+ + 28480 + http://article.gmane.org/gmane.mail.postfix.policyd-weight/815 + http://article.gmane.org/gmane.mail.postfix.policyd-weight/823 + + + 2008-03-27 + 2008-04-06 + +
+ powerdns-recursor -- DNS cache poisoning -- cgit v1.2.3