CVE-2013-4223: Gentoo Nullmailer

Medium severity, CVSS 5.0. EPSS: 1.3% chance of exploitation in the next 30 days.

The Gentoo Nullmailer package before 1.11-r2 uses world-readable permissions for /etc/nullmailer/remotes, which allows local users to obtain SMTP authentication credentials by reading the file.

Affected products

  • Gentoo Nullmailer: version 1.11 only

Published 2014-05-23. Last modified 2026-06-16.