[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: #506353 CVE-2008-5312/3: mailscanner might allow local users to overwrite arbitrary files via a symlink attack



Hi,
* Simon Walter <simon.walter@hp-factory.de> [2008-12-15 22:38]:
> as you can see here[1] I have got a little security problem with the
> package[2] I maintain.
> 
> Upstream has fixed the problem quite fast[3] in the last release (4.74.8-1).
> I can easily bring this into sid, but what's about lenny?
> 
> lenny (testing) 4.68.8-1: all 
> 
> Is there a chance to get 4.74.8 unblocked? Is it very unwise to even
> try so?

Ask the release team ;)

> Do I have to contact security team and work on a fix for
> 4.68.8?

Yes would be nice :) Mail secure-testing-team@lists.alioth.debian.org.

Cheers
Nico
-- 
Nico Golde - http://ngolde.de - nion@jabber.ccc.de - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.
http://people.debian.org/~nion/sponsoring-checklist.html

Attachment: pgpVcix05Gseu.pgp
Description: PGP signature


Reply to: