CVE Vulnerabilities

CVE-2005-2655

Published: Aug 30, 2005 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

lockmail in maildrop before 1.5.3 does not drop privileges before executing commands, which allows local users to gain privileges via command line arguments.

Affected Software

Name Vendor Start Version End Version
Maildrop Maildrop 0.50 (including) 0.50 (including)
Maildrop Maildrop 0.51 (including) 0.51 (including)
Maildrop Maildrop 0.51b (including) 0.51b (including)
Maildrop Maildrop 0.51c (including) 0.51c (including)
Maildrop Maildrop 0.54 (including) 0.54 (including)
Maildrop Maildrop 0.54a (including) 0.54a (including)
Maildrop Maildrop 0.54b (including) 0.54b (including)
Maildrop Maildrop 0.55 (including) 0.55 (including)
Maildrop Maildrop 0.55a (including) 0.55a (including)
Maildrop Maildrop 0.55b (including) 0.55b (including)
Maildrop Maildrop 0.55c (including) 0.55c (including)
Maildrop Maildrop 0.60 (including) 0.60 (including)
Maildrop Maildrop 0.61 (including) 0.61 (including)
Maildrop Maildrop 0.62 (including) 0.62 (including)
Maildrop Maildrop 0.63 (including) 0.63 (including)
Maildrop Maildrop 0.64 (including) 0.64 (including)
Maildrop Maildrop 0.65 (including) 0.65 (including)
Maildrop Maildrop 0.70 (including) 0.70 (including)
Maildrop Maildrop 0.71 (including) 0.71 (including)
Maildrop Maildrop 0.72 (including) 0.72 (including)
Maildrop Maildrop 0.73 (including) 0.73 (including)
Maildrop Maildrop 0.74 (including) 0.74 (including)
Maildrop Maildrop 0.75 (including) 0.75 (including)
Maildrop Maildrop 0.76 (including) 0.76 (including)
Maildrop Maildrop 0.99.1 (including) 0.99.1 (including)
Maildrop Maildrop 0.99.2 (including) 0.99.2 (including)
Maildrop Maildrop 1.0 (including) 1.0 (including)
Maildrop Maildrop 1.1 (including) 1.1 (including)
Maildrop Maildrop 1.2 (including) 1.2 (including)
Maildrop Maildrop 1.2.1 (including) 1.2.1 (including)
Maildrop Maildrop 1.2.2 (including) 1.2.2 (including)
Maildrop Maildrop 1.3.0 (including) 1.3.0 (including)
Maildrop Maildrop 1.3.1 (including) 1.3.1 (including)
Maildrop Maildrop 1.3.3 (including) 1.3.3 (including)
Maildrop Maildrop 1.3.4 (including) 1.3.4 (including)
Maildrop Maildrop 1.3.5 (including) 1.3.5 (including)
Maildrop Maildrop 1.3.6 (including) 1.3.6 (including)
Maildrop Maildrop 1.3.7 (including) 1.3.7 (including)
Maildrop Maildrop 1.3.8 (including) 1.3.8 (including)
Maildrop Maildrop 1.3.9 (including) 1.3.9 (including)
Maildrop Maildrop 1.4.0 (including) 1.4.0 (including)
Maildrop Maildrop 1.5.0 (including) 1.5.0 (including)
Maildrop Maildrop 1.5.1 (including) 1.5.1 (including)
Maildrop Maildrop 1.5.2 (including) 1.5.2 (including)
Maildrop Ubuntu dapper *
Maildrop Ubuntu devel *
Maildrop Ubuntu edgy *
Maildrop Ubuntu feisty *

References