3 messages in net.sourceforge.lists.courier-sqwebmailRe: [sqwebmail] sqwebpasswd installat...
FromSent OnAttachments
Brian CandlerApr 23, 2005 3:33 am 
Sam VarshavchikApr 23, 2005 5:16 am 
Brian CandlerApr 23, 2005 6:35 am 
Actions with this message:
Paste this link in email or IM:
Paste this link in email or IM:
Atom feed for this thread
Paste this URL into your reader:
Subject:Re: [sqwebmail] sqwebpasswd installation bugActions...
From:Sam Varshavchik (mrs@courier-mta.com)
Date:Apr 23, 2005 5:16:47 am
List:net.sourceforge.lists.courier-sqwebmail

Brian Candler writes:

It does seem to me that sqwebpasswd is something of a system security hole, as it's unprotected and can bump you up into the wheel group (currently), or the mail group (when this bug is fixed).

The source code for sqwebpasswd.c is tiny. Exactly how do you believe it can do that?