Re: OpenSMTPD 6.6.4p1 released: addresses CRITICAL vulnerability

2020-02-25 Thread Denis Fateyev
Oh, I see. They added an amendment to the end. Last-minute note: on February 9, 2020, opensmtpd-6.6.2p1-1.fc31 was released and correctly made smtpctl set-group-ID smtpq, instead of set-group-ID root. Rather strange that they haven't managed to update packages for two weeks before checking anythi

Re: OpenSMTPD 6.6.4p1 released: addresses CRITICAL vulnerability

2020-02-25 Thread Denis Fateyev
Beside the real vulnerability, what is interesting that Qualys used an outdated Fedora package to prepare the report: On Linux, this vulnerability is generally not exploitable because /proc/sys/fs/protected_hardlinks prevents attackers from creating hardlinks to files they do not own. On Fedora 31