Re: [Exim] Exim filters and potential security issues.

Pàgina inicial
Delete this message
Reply to this message
Autor: Tony Finch
Data:  
A: masta
CC: exim-users
Assumpte: Re: [Exim] Exim filters and potential security issues.
Nico Erfurth <masta@???> wrote:
>
>2.) Exim filters have a nice feature, they allow to log with the
>     logfile/logwrite commands, BUT in a virtual only setup, this can
>     lead to problems. When all users are using the same UID and are
>     allowed to use exim-filters (as on my machine), an attacker could be
>     able to use logwrite to write mail into some other users maildir, or
>     doing other REALLY worse things.


forbid_filter_logwrite

Tony.
--
f.a.n.finch <dot@???> http://dotat.at/
SHANNON: VARIABLE 3 OR 4, BECOMING NORTHERLY 5 IN WEST FOR A TIME. RAIN IN
EAST. MODERATE OR GOOD.