cyrus With postfix and Procmail...

- AV AC AU C I A
发布: 2000-07-05
修订: 2025-04-13

A vulnerability exists in one method in which the cyrus IMAP server can be made to work with the Postfix MTA. By failing to check the contents of certain user supplied fields, its possible to cause procmail to execute shell backtick expansion (``), allowing the execution of arbitrary commands as the cyrus user. This does not represent a vulnerability in cyrus, procmail or postfix, but instead a vulnerability in one method for integrating these tools.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息