aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorrafan <rafan@FreeBSD.org>2008-04-06 16:50:37 +0800
committerrafan <rafan@FreeBSD.org>2008-04-06 16:50:37 +0800
commitf29755f74021d623e3671b29c948ead5c3e33715 (patch)
treec2280cbffd9fb9987ac26633f33707d32596fb1b
parent9691ae351c80ad03f2adb80ef2b531a93ce39264 (diff)
downloadfreebsd-ports-gnome-f29755f74021d623e3671b29c948ead5c3e33715.tar.gz
freebsd-ports-gnome-f29755f74021d623e3671b29c948ead5c3e33715.tar.zst
freebsd-ports-gnome-f29755f74021d623e3671b29c948ead5c3e33715.zip
- Add entry for mail/postfix-policyd-weight
PR: ports/122194 Reviewed by: ports-security (miwi)
-rw-r--r--security/vuxml/vuln.xml28
1 files changed, 28 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml
index f66d2750e7a3..289ea8b79a10 100644
--- a/security/vuxml/vuln.xml
+++ b/security/vuxml/vuln.xml
@@ -34,6 +34,34 @@ Note: Please add new entries to the beginning of this file.
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
+ <vuln vid="072a53e0-0397-11dd-bd06-0017319806e7">
+ <topic>postfix-policyd-weight -- working directory symlink vulnerability</topic>
+ <affects>
+ <package>
+ <name>postfix-policyd-weight</name>
+ <range><lt>0.1.14.17</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>postfix-policyd-weight does not check for symlink for its working
+ directory. If the working directory is not already setup by the
+ super root, an unprivileged user can link it to another directories
+ in the system. This results in ownership/permission changes on the
+ target directory.</p>
+ </body>
+ </description>
+ <references>
+ <bid>28480</bid>
+ <url>http://article.gmane.org/gmane.mail.postfix.policyd-weight/815</url>
+ <url>http://article.gmane.org/gmane.mail.postfix.policyd-weight/823</url>
+ </references>
+ <dates>
+ <discovery>2008-03-27</discovery>
+ <entry>2008-04-06</entry>
+ </dates>
+ </vuln>
+
<vuln vid="b21790a5-02fb-11dd-bd06-0017319806e7">
<topic>powerdns-recursor -- DNS cache poisoning</topic>
<affects>