From 9452a6e87b6c2c70513bc47a2470bf9f1168920e Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Sat, 13 Jun 2020 10:39:22 +0100 Subject: gentoo resync : 13.06.2020 --- metadata/glsa/glsa-202006-12.xml | 46 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 46 insertions(+) create mode 100644 metadata/glsa/glsa-202006-12.xml (limited to 'metadata/glsa/glsa-202006-12.xml') diff --git a/metadata/glsa/glsa-202006-12.xml b/metadata/glsa/glsa-202006-12.xml new file mode 100644 index 000000000000..d55a1902c21c --- /dev/null +++ b/metadata/glsa/glsa-202006-12.xml @@ -0,0 +1,46 @@ + + + + GNU Mailutils: Privilege escalation + A vulnerability has been found in GNU Mailutils allowing privilege + escalation. + + mailutils + 2020-06-13 + 2020-06-13 + 700806 + local + + + 3.8 + 3.8 + + + +

The GNU Mailutils are a collection of mail-related utilities, including + an IMAP4 server (imap4d). +

+
+ +

GNU Mailutils runs maidag by default with setuid root permissions.

+
+ +

An attacker can use this to write to arbitrary files as root.

+
+ +

There is no known workaround at this time.

+
+ +

All GNU Mailutils users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-mail/mailutils-3.8" + +
+ + CVE-2019-18862 + + sam_c + sam_c +
-- cgit v1.2.3