CVE Vulnerabilities

CVE-2010-0301

Published: Feb 04, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
3.3 MODERATE
AV:L/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

main.C in maildrop 2.3.0 and earlier, when run by root with the -d option, uses the gid of root for execution of the .mailfilter file in a users home directory, which allows local users to gain privileges via a crafted file.

Affected Software

NameVendorStart VersionEnd Version
MaildropMaildrop*2.3.0 (including)
MaildropMaildrop0.50 (including)0.50 (including)
MaildropMaildrop0.51 (including)0.51 (including)
MaildropMaildrop0.51b (including)0.51b (including)
MaildropMaildrop0.51c (including)0.51c (including)
MaildropMaildrop0.54 (including)0.54 (including)
MaildropMaildrop0.54a (including)0.54a (including)
MaildropMaildrop0.54b (including)0.54b (including)
MaildropMaildrop0.55 (including)0.55 (including)
MaildropMaildrop0.55a (including)0.55a (including)
MaildropMaildrop0.55b (including)0.55b (including)
MaildropMaildrop0.55c (including)0.55c (including)
MaildropMaildrop0.60 (including)0.60 (including)
MaildropMaildrop0.61 (including)0.61 (including)
MaildropMaildrop0.62 (including)0.62 (including)
MaildropMaildrop0.63 (including)0.63 (including)
MaildropMaildrop0.64 (including)0.64 (including)
MaildropMaildrop0.65 (including)0.65 (including)
MaildropMaildrop0.70 (including)0.70 (including)
MaildropMaildrop0.71 (including)0.71 (including)
MaildropMaildrop0.72 (including)0.72 (including)
MaildropMaildrop0.73 (including)0.73 (including)
MaildropMaildrop0.74 (including)0.74 (including)
MaildropMaildrop0.75 (including)0.75 (including)
MaildropMaildrop0.76 (including)0.76 (including)
MaildropMaildrop0.99.1 (including)0.99.1 (including)
MaildropMaildrop0.99.2 (including)0.99.2 (including)
MaildropMaildrop1.0 (including)1.0 (including)
MaildropMaildrop1.1 (including)1.1 (including)
MaildropMaildrop1.2 (including)1.2 (including)
MaildropMaildrop1.2.1 (including)1.2.1 (including)
MaildropMaildrop1.2.2 (including)1.2.2 (including)
MaildropMaildrop1.3.0 (including)1.3.0 (including)
MaildropMaildrop1.3.1 (including)1.3.1 (including)
MaildropMaildrop1.3.3 (including)1.3.3 (including)
MaildropMaildrop1.3.4 (including)1.3.4 (including)
MaildropMaildrop1.3.5 (including)1.3.5 (including)
MaildropMaildrop1.3.6 (including)1.3.6 (including)
MaildropMaildrop1.3.7 (including)1.3.7 (including)
MaildropMaildrop1.3.8 (including)1.3.8 (including)
MaildropMaildrop1.3.9 (including)1.3.9 (including)
MaildropMaildrop1.4.0 (including)1.4.0 (including)
MaildropMaildrop1.5.0 (including)1.5.0 (including)
MaildropMaildrop1.5.1 (including)1.5.1 (including)
MaildropMaildrop1.5.2 (including)1.5.2 (including)
MaildropMaildrop1.6.2 (including)1.6.2 (including)
MaildropMaildrop1.6.3 (including)1.6.3 (including)
MaildropMaildrop1.7.0 (including)1.7.0 (including)
MaildropMaildrop1.8.1 (including)1.8.1 (including)
MaildropMaildrop2.0.0 (including)2.0.0 (including)
MaildropMaildrop2.0.1 (including)2.0.1 (including)
MaildropMaildrop2.0.2 (including)2.0.2 (including)
MaildropMaildrop2.0.3 (including)2.0.3 (including)
MaildropMaildrop2.0.4 (including)2.0.4 (including)
MaildropMaildrop2.1 (including)2.1 (including)
MaildropMaildrop2.2 (including)2.2 (including)
MaildropUbuntuartful*
MaildropUbuntudapper*
MaildropUbuntuhardy*
MaildropUbuntuintrepid*
MaildropUbuntujaunty*
MaildropUbuntukarmic*
MaildropUbuntulucid*
MaildropUbuntumaverick*
MaildropUbuntunatty*
MaildropUbuntuoneiric*
MaildropUbuntuprecise*
MaildropUbuntuquantal*
MaildropUbunturaring*
MaildropUbuntusaucy*
MaildropUbuntuupstream*
MaildropUbuntuutopic*
MaildropUbuntuvivid*
MaildropUbuntuwily*
MaildropUbuntuyakkety*
MaildropUbuntuzesty*

References