From e2f5dc151e2e79058e93924e6d35510557f0535d Mon Sep 17 00:00:00 2001 From: David Woodhouse Date: Sat, 11 Dec 2010 14:09:17 +0000 Subject: Check configure file permissions even for non-default files if still privileged (Bug 1044, CVE-2010-4345) --- doc/doc-txt/ChangeLog | 5 +++++ 1 file changed, 5 insertions(+) (limited to 'doc/doc-txt') diff --git a/doc/doc-txt/ChangeLog b/doc/doc-txt/ChangeLog index 99a6f176b..0063c6be0 100644 --- a/doc/doc-txt/ChangeLog +++ b/doc/doc-txt/ChangeLog @@ -78,6 +78,11 @@ DW/22 Bugzilla 1044: CVE-2010-4345 - partial fix: restrict default behaviour of CONFIGURE_OWNER and CONFIGURE_GROUP options to no longer allow a configuration file which is writeable by the Exim user or group. +DW/23 Bugzilla 1044: CVE-2010-4345 - part two: extend checks for writeability + of configuration files to cover files specified with the -C option if + they are going to be used with root privileges, not just the default + configuration file. + Exim version 4.72 ----------------- -- cgit v1.2.3