Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Debian 2.1: Security Advisory on Majordomo Local Exploit Risk

debian
Calendar Grey June 3, 2000
Debian Logo
Individuals with physical access can exploit majordomo on Debian 2.1 to execute unapproved scripts and alter file permissions.
Any local user can trick majordomo into executing arbitrary code or to create or write files as the majordomo user anywhere on the filesystem.

Summary


Package : majordomo
Problem type : local exploit
Debian-specific: no

The majordomo package as shipped in the non-free section accompanying
Debian GNU/Linux 2.1/slink allows any local user to trick majordomo into
executing arbitrary code or to create or write files as the majordomo user
anywhere on the filesystem.

This is a documented issue and the advised work around it to either have
no untrusted users on a system running majordomo or to use a setuid
wrapper that the MTA delivery agent can run.
suboptimal solution.

We feel that those options are not a good solution, but unfortunately the
majordomo license does not allow us to fix these problems and distribute a
fixed version. As a result we have decided to remove majordomo from our
archives.

If you are using majordomo we recommend that you replace it with one
of the many other mailing-list tools available such as fml, mailman
or smartlist.

- --
For apt-get: deb https://www.debian.org/security/ stable updates
For dpkg-ftp: dists/stable/updates


...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here