SciLinux: CVE-2007-2873 spamassassin SL5.x, SL4.x i386/x86_64 (fwd)
Summary
Date: Wed, 13 Jun 2007 17:32:10 -0500Reply-To: Connie SiehSender: Security Errata for Scientific Linux From: Connie Sieh Subject: Security ERRATA for spamassassin on SL5.x, SL4.x i386/x86_64 (fwd)Comments: To: scientific Synopsis: Moderate: spamassassin security updateIssue date: 2007-06-13CVE Names: CVE-2007-2873Description:Martin Krafft discovered a symlink issue in SpamAssassin that affectscertain non-default configurations. A local user could use this flaw tocreate or overwrite files writable by the spamd process (CVE-2007-2873).SL 4.x: SRPMS: spamassassin-3.1.9-1.el4.src.rpm i386: spamassassin-3.1.9-1.el4.i386.rpm x86_64: spamassassin-3.1.9-1.el4.x86_64.rpmSL 5.x: SRPMS: spamassassin-3.1.9-1.el5.src.rpm i386: spamassassin-3.1.9-1.el5.i386.rpm x86_64: spamassassin-3.1.9-1.el5.x86_64.rpm--Connie Sieh--Troy Dawson