[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: New free secure open source IBM mailer aka Vmailer aka Postfix



> ??? ru sure? they mention some other problems regarding world writable
> spool dir.
> btw, directory is with sticky bit, just like any /tmp on any u*x box.

Basically, for non-bugtraq-readers: Postfix deletes all files from the
queue that have link count more than 1. If you manage to hardlink one's
file to outside of the directory, the victim's mail will be dropped. Read
bugtraq archives for more info.

Wenema confirmed existance of such an oversight on Bugtraq, IIRC.
Errare humanum est.
-- 
frodo@sharat.co.il	\/  There shall be counsels taken
Stanislav Malyshev	/\  Stronger than Morgul-spells
phone +972-2-6245112	/\  		JRRT LotR.
http://sharat.co.il/frodo/	whois:!SM8333