October 18, 2001

Debian: Secuity advisory for procmail

Author: JT Smith

Posted at LWN.net: "Using older versions of procmail it was possible to make procmail
crash by sending it signals. On systems where procmail is installed
setuid this could be exploited to obtain unauthorized privileges.

This problem has been fixed in version 3.20 by the upstream
maintainer, included in Debian unstable, and was ported back to
version 3.15.2 which is available for for the stable Debian GNU/Linux


  • Linux
