Security Advisory
CVE-2013-4223
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
The Gentoo Nullmailer package before 1.11-r2 uses world-readable permissions for /etc/nullmailer/remotes, which allows local users to obtain SMTP authentication credentials by reading the file.