Software
DirectAdmin Version: 1.40.3
Exim Version: 4.76
Linux Centos 5.6 x86_64
I found a critical bug when you try to change a password of an user with overquota (over used disk space).
DirectAdmin will try to modify the file in /home/user1/.shadow but the file is left empty because it can not be modified (the modification is rejected by the overquota status)
This generates an important issue that allows the smtp authentication with random password for that system user because exim uses /home/user1/.shadow for password validation and when this file is empty exim accept the login with any password
I think that this is an important issue, but I can't know if it affect all DirectAdmins or only to me...
Anyone can confirm the bug?
DirectAdmin Version: 1.40.3
Exim Version: 4.76
Linux Centos 5.6 x86_64
I found a critical bug when you try to change a password of an user with overquota (over used disk space).
DirectAdmin will try to modify the file in /home/user1/.shadow but the file is left empty because it can not be modified (the modification is rejected by the overquota status)
This generates an important issue that allows the smtp authentication with random password for that system user because exim uses /home/user1/.shadow for password validation and when this file is empty exim accept the login with any password
I think that this is an important issue, but I can't know if it affect all DirectAdmins or only to me...
Anyone can confirm the bug?