lockmail in maildrop before 1.5.3 does not drop privileges before executing commands, which allows local users to gain privileges via command line arguments.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: debian

Published: 2005-08-30T04:00:00Z

Updated: 2024-09-17T00:56:09.991Z

Reserved: 2005-08-22T00:00:00Z

Link: CVE-2005-2655

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2005-08-30T17:03:00.000

Modified: 2008-09-05T20:52:20.423

Link: CVE-2005-2655

cve-icon Redhat

No data.