shouldn't we mark pkgsrc/mail/qpopper (2.53) broken for local exploit, and try to upgrade to 3.02? http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-05-22&msg=p04320305b5511470392c@[192.168.1.5] itojun