[Simon Walter] Bug#506353: mailscanner: many scripts allow local users to overwrite arbitrary files, and more, via symlink attacks

Kai Schaetzl maillists at conactive.com
Fri Dec 12 14:12:38 GMT 2008


Julian Field wrote on Fri, 12 Dec 2008 11:53:15 +0000:

> That's because that's not what you need to add, it was your guess at 
> what you needed to add :-)

It was almost correct, good guess by Phil.

> Download the -2 release and you'll be fine, that has the correct line at 
> the top I believe.

Installed, and it's processing. Good thing about all these rapid 
deployments after a while of not updating is that I wrote me a script now 
that just needs the version no. and takes care of the rest.

Have a healthy weekend!

Kai

-- 
Kai Schätzl, Berlin, Germany
Get your web at Conactive Internet Services: http://www.conactive.com





More information about the MailScanner mailing list