CVE-2026-104658
Beschrijving NL
De Linux live-update apply helper (hmailserver-update) van Progressive Robot hMailServer 6.3.4 en 6.3.5 wordt als root uitgevoerd op een aanvraagbestand dat is geschreven door het onbevoorrechte hmailserver-serviceaccount, en nam van dat verzoek het programma dat werd gebruikt om de handtekening van een AppImage-update te verifiëren en de systemd-eenheid om te stoppen voordat de bestanden van het serviceaccount werden gelezen. Een aanvaller die al code uitvoert als het hmailserver-serviceaccount, bijvoorbeeld via een andere kwetsbaarheid in de mailserver, kan daardoor willekeurige code uitvoeren als root, op elke Linux-installatie waar de pad-eenheid van de live-update actief is - de standaard voor de .deb- en .rpm-pakketten van het project - en op AppImage-installaties die onder die eenheid worden uitgevoerd.
Origineel (Engels) tonen
The Linux live-update apply helper (hmailserver-update) of Progressive Robot hMailServer 6.3.4 and 6.3.5 runs as root on a request file written by the unprivileged hmailserver service account, and took from that request the program used to verify an AppImage update's signature and the systemd unit to stop before reading the service account's files. An attacker who already runs code as the hmailserver service account, for example through another flaw in the mail server, can therefore have arbitrary code executed as root, on any Linux installation where the live update's path unit is active - the default for the project's .deb and .rpm packages - and on AppImage installations run under that unit.