I strongly dislike adding a new setgid binary to the system, writing
these requires care and diligence. Adding setgid after the fact is
extremely dangerous.

Re-using an existing group is also dangerous; group mail for example has
write access to /var/mail.

This might just be the limit of what this tool is prepared to handle;
systems with untrusted users maybe should stick to exim or postfix or
similar.

Thanks

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/654065

Title:
  ssmtp.conf security

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ssmtp/+bug/654065/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to