Re: Qpopper v4.0.x poppassd local root exploit

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



I'm working on a fix, but would like to point out that poppassd is not built nor installed by default. Also, poppassd is an inherently insecure protocol that sends both the current and new passwords in the clear, and in general should only be used with full understanding of the situation.
--
Randall Gellens
rg_public.1@flagg.qualcomm.com
Opinions are personal; facts are suspect; I speak for myself only

[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux