Title : Debian Security Update Fixes Multiple Qpopper Vulnerabilities VUPEN ID : VUPEN/ADV-2005-0619 CVE ID : CVE-2005-1151 - CVE-2005-1152 CWE ID : CWE-
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2005-05-25
Technical Description
Debian has released a security patch to correct two vulnerabilities identified in Qpopper. The problem is that Qpopper does not properly drop privileges to process local files from normal users and can be forced to create group or world writeable files. A malicious local attacker could exploit Qpopper to overwrite arbitrary files as root or create new files which are group or world writeable.
Debian GNU/Linux 3.0 (woody) - Upgrade to version 4.0.4-2.woody.5
Debian GNU/Linux unstable (sid) - Upgrade to version 4.0.5-4sarge1
Debian GNU/Linux testing (sarge) - Upgrade to version 4.0.5-4sarge1 References