Bug#469457: dovecot-imapd: allows to read other users' mboxes in /var/mail

2008-03-06 Thread Nico Golde
tags 469457 + patch severity 469457 grave thanks Hi, you can find a patch for this on: http://dovecot.org/patches/1.0/dovecot-1.0.10.mail_priv_groups.diff Cheers Nico -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-

Bug#469457: dovecot-imapd: allows to read other users' mboxes in /var/mail

2008-03-05 Thread Jeremie Bouttier
Package: dovecot-imapd Severity: critical Tags: security Justification: root security hole I believe all versions of Dovecot in Debian are concerned by this warning : http://dovecot.org/list/dovecot/2008-March/029196.html On fairly standard Debian installations (Etch & Lenny) with mail delivered