USN-226-1: Courier vulnerability
10 December 2005
Courier vulnerability
Releases
Details
Patrick Cheong Shu Yang discovered a flaw in the user account handling
of courier-authdaemon. After successful authorization, the Courier
mail server granted access to deactivated accounts.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 5.10
-
courier-authdaemon
-
Ubuntu 5.04
-
courier-authdaemon
-
Ubuntu 4.10
-
courier-authdaemon
-
In general, a standard system update will make all the necessary changes.