GNU Mailutils: Privilege escalation A vulnerability has been found in GNU Mailutils allowing privilege escalation. mailutils 2020-06-13 2020-06-13 700806 local 3.8 3.8

The GNU Mailutils are a collection of mail-related utilities, including an IMAP4 server (imap4d).

GNU Mailutils runs maidag by default with setuid root permissions.

An attacker can use this to write to arbitrary files as root.

There is no known workaround at this time.

All GNU Mailutils users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-mail/mailutils-3.8"
CVE-2019-18862 sam_c sam_c