[Dovecot] SetUID check problem

2009-10-27 Thread Thomas Berezansky
Running dovecot 1.2.4 on FreeBSD using Postfix. Everything works fine normally, but deliver is executable by world. This is not normally a problem, as I don't run deliver SetUID root. But for whatever reason, when deliver is called by something that IS SetUID root I get the following error:

Re: [Dovecot] SetUID check problem

2009-10-27 Thread Timo Sirainen
On Tue, 2009-10-27 at 09:03 -0400, Thomas Berezansky wrote: But for whatever reason, when deliver is called by something that IS SetUID root I get the following error: /usr/local/libexec/dovecot/deliver must not be both world-executable and setuid-root. This allows root exploits. See