INetCop Security Advisory #2003-0x82-016 – Qpopper v4.0.x poppassd, the utility that allows users to change their mail passwords, is setuid root and allows for a definable path to smbpasswd. In doing so, a local attacker can easily escalate to root privileges.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/31076/qpoppassd.txt
Source: https://packetstormsecurity.com/files/31076/qpoppassd.txt.html

