Description
qpopper 4.0.5 and earlier does not properly drop privileges before processing certain user-supplied files, which allows local users to overwrite or create arbitrary files as root.
Affected products
- Debian / qpopper4.0.4
- Debian / qpopper4.0.5 – 4.0.5
References
- VENDOR_ADVISORYhttp://secunia.com/advisories/15505
- VENDOR_ADVISORYhttp://secunia.com/advisories/15478
- MISChttp://bugs.gentoo.org/show_bug.cgi?id=90622
- VENDOR_ADVISORYhttp://www.debian.org/security/2005/dsa-728
- VENDOR_ADVISORYhttp://secunia.com/advisories/15475
- MISChttp://www.gentoo.org/security/en/glsa/glsa-200505-17.xml