CVE-2013-4223

Gentoo Nullmailer - Access Control

Title source: rule

Description

The Gentoo Nullmailer package before 1.11-r2 uses world-readable permissions for /etc/nullmailer/remotes, which allows local users to obtain SMTP authentication credentials by reading the file.

Scores

EPSS 0.0043
EPSS Percentile 62.4%

Classification

CWE
CWE-264
Status draft

Affected Products (1)

gentoo/nullmailer

Timeline

Published May 23, 2014
Tracked Since Feb 18, 2026