Bug#330123: qpopper: poppassd local root exploit?

2005-09-26 Thread Florian Weimer
Does the Debian package ship poppassd? I don't think so: $ dpkg -L qpopper | grep bin /usr/bin /usr/bin/popauth /usr/sbin /usr/sbin/in.qpopper $ dpkg -l qpopper [...] ii qpopper4.0.5-4Enhanced Post Office Protocol server (POP3) $ However, password/Makefile.in does indeed insta

Bug#330123: qpopper: poppassd local root exploit?

2005-09-25 Thread Martin Pitt
Package: qpopper Version: 4.0.5-4 Severity: important Tags: security Hi! On full-disclosure, there was a posting about a local root exploit in Qpopper: http://lists.grok.org.uk/pipermail/full-disclosure/2005-September/037377.html I haven't looked into this issue myself, so I leave the severit