Bug#984810: courier-authlib: authtest can access user data information from normal users accoun

2021-03-08 Thread PICCORO McKAY Lenz
El lun, 8 de mar. de 2021 a la(s) 14:56, Markus Wanner (mar...@bluegap.ch) escribió: > not very different from a `cat /etc/passwd`). but we can use the tool to parse brute force attacks in combination with authpasswd tool that is also another case of! so an important update for oldstable, stable an

Bug#984810: courier-authlib: authtest can access user data information from normal users accoun

2021-03-08 Thread Markus Wanner
Control: tags -1 + confirmed Control: severity -1 important On 08.03.21 16:50, PICCORO McKAY Lenz wrote: Currently as normal user, it can be accessed to users database if we setup mysql, postgres or sqlite, inclusively ldap setups.. i mean, a limited account can query users mail data to made so

Bug#984810: courier-authlib: authtest can access user data information from normal users accoun

2021-03-08 Thread PICCORO McKAY Lenz
Package: courier-authlib Version: 0.71.0-1 Tags: upstream security buster stretch bullseye Justification: user security hole Severity: grave Usertags: security The /usr/sbin/auth is a program that can test from a installation setup if authlib daemon are working without the complete courier suite i