[courier-users] Unautorized access vulnerability?

2005-12-08 Thread Randy Smith
Greetings, I recently saw a vulnerability announcement on SecurityFocus about a Unauthorized Access Vulnerability in courier 0.37.3. 0.47 and 0.52.1. (http://www.securityfocus.com/bid/15771) The discussion of the exploit is pretty vague. Can someone shed some light on what is being reported

Re: [courier-users] Unautorized access vulnerability?

2005-12-08 Thread Jay Lee
Randy Smith said: I recently saw a vulnerability announcement on SecurityFocus about a Unauthorized Access Vulnerability in courier 0.37.3. 0.47 and 0.52.1. (http://www.securityfocus.com/bid/15771) The discussion of the exploit is pretty vague. Can someone shed some light on what is being

Re: [courier-users] Unautorized access vulnerability?

2005-12-08 Thread Stefan Hornburg
Jay Lee wrote: Randy Smith said: I recently saw a vulnerability announcement on SecurityFocus about a Unauthorized Access Vulnerability in courier 0.37.3. 0.47 and 0.52.1. (http://www.securityfocus.com/bid/15771) The discussion of the exploit is pretty vague. Can someone shed some light on

Re: [courier-users] Unautorized access vulnerability?

2005-12-08 Thread Stefan Hornburg
Randy Smith wrote: Greetings, I recently saw a vulnerability announcement on SecurityFocus about a Unauthorized Access Vulnerability in courier 0.37.3. 0.47 and 0.52.1. (http://www.securityfocus.com/bid/15771) The discussion of the exploit is pretty vague. Can someone shed some light on what

Re: [courier-users] Unautorized access vulnerability?

2005-12-08 Thread Sam Varshavchik
Stefan Hornburg writes: Looks like it's only if your using auth_pam. I have seen no verification the issue is present in 0.52.1 since the courier-authlib split off (so actually, it'd be a bug in courier-authlib, not courier-0.52.1). Sam may have further details but it looks like this is