Re: [SECURITY] [DSA 1981-1] New maildrop packages fix privilege escalation

2010-01-28 Thread Antti-Juhani Kaijanaho
On Thu, Jan 28, 2010 at 12:37:52PM +0100, Steffen Joeris wrote: For the stable distribution (lenny), this problem has been fixed in version 2.0.4-3+lenny1. This update appears to have dropped the hard dependency on courier-authlib. As a result, mail starts bouncing. -- Antti-Juhani

Re: [SECURITY] [DSA 1981-1] New maildrop packages fix privilege escalation

2010-01-28 Thread Konstantin Filtschew
The behavior of the etch package changed too. Do not install the package on production system yet. The limit in /etc/postfix/main.cf stopped working: maildrop_destination_recipient_limit= 1 Almost all E-Mails are rejected and sender get errors like this: u...@doamin.com: user unknown. Command

Re: [SECURITY] [DSA 1981-1] New maildrop packages fix privilege escalation

2010-01-28 Thread Steffen Joeris
On Thu, 28 Jan 2010 01:10:19 pm Antti-Juhani Kaijanaho wrote: On Thu, Jan 28, 2010 at 12:37:52PM +0100, Steffen Joeris wrote: For the stable distribution (lenny), this problem has been fixed in version 2.0.4-3+lenny1. This update appears to have dropped the hard dependency on

Re: [SECURITY] [DSA 1981-1] New maildrop packages fix privilege escalation

2010-01-28 Thread Steffen Joeris
On Thu, 28 Jan 2010 02:27:38 pm Konstantin Filtschew wrote: The behavior of the etch package changed too. Do not install the package on production system yet. The limit in /etc/postfix/main.cf stopped working: maildrop_destination_recipient_limit= 1 Almost all E-Mails are rejected and

Re: [SECURITY] [DSA 1981-1] New maildrop packages fix privilege escalation

2010-01-28 Thread Willi Mann
Hi! Did anybody check whether courier-maildrop is also affected by this issue? This should be the same codebase (same author), except maybe some different compile time options / different version. WM -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of

Re: [SECURITY] [DSA 1981-1] New maildrop packages fix privilege escalation

2010-01-28 Thread Steffen Joeris
On Thu, 28 Jan 2010 10:40:06 pm Willi Mann wrote: Hi! Did anybody check whether courier-maildrop is also affected by this issue? This should be the same codebase (same author), except maybe some different compile time options / different version. courier-maildrop is not vulnerable to this