Oh, I see. They added an amendment to the end.
Last-minute note: on February 9, 2020, opensmtpd-6.6.2p1-1.fc31 was
released and correctly made smtpctl set-group-ID smtpq, instead of
set-group-ID root.
Rather strange that they haven't managed to update packages for two
weeks before checking anythi
Beside the real vulnerability, what is interesting that Qualys used an
outdated Fedora package to prepare the report:
On Linux, this vulnerability is generally not exploitable because
/proc/sys/fs/protected_hardlinks prevents attackers from creating
hardlinks to files they do not own. On Fedora 31