The Gentoo Nullmailer package prior to 1.11-r2 uses world-readable permissions for /etc/nullmailer/remotes, which allows local users to obtain SMTP authentication credentials by reading the file.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
gentoo nullmailer 1.11 |