[Dovecot] [Dovecot-news] Security issue #5: mail_extra_groups setting is often used insecurely

Timo Sirainen tss at iki.fi
Wed Mar 5 00:29:40 EET 2008


On Tue, 2008-03-04 at 17:31 +0100, Jérémie Bouttier wrote:
> > a) Upgrade to v1.0.11 and use the new mail_privileged_group setting
> > instead of mail_extra_groups.
> 
> We tried this but now the mail.log has a number of lines :
> « dovecot: IMAP(someuser): open(/var/mail/.temp.XXXX) failed: Permission 
> denied »

Oh, this is actually harmless. You can get rid of it (and improve the
performance) by setting dotlock_use_excl=yes.

But maybe I should release v1.0.12 anyway with that error message
silenced..


-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://dovecot.org/pipermail/dovecot/attachments/20080305/9c468c26/attachment-0001.bin 


More information about the dovecot mailing list