[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-2936Date: (C)2008-08-18   (M)2023-12-22


Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message. NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.2
Exploit Score: 1.9
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: HIGH
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1020700
http://www.securityfocus.com/archive/1/495474/100/0/threaded
http://www.securityfocus.com/archive/1/495632/100/0/threaded
http://www.securityfocus.com/archive/1/495882/100/0/threaded
BID-30691
SECUNIA-31469
SECUNIA-31474
SECUNIA-31477
SECUNIA-31485
SECUNIA-31500
SECUNIA-31530
SECUNIA-32231
SREASON-4160
EXPLOIT-DB-6337
ADV-2008-2385
DSA-1629
FEDORA-2008-8593
FEDORA-2008-8595
GLSA-200808-12
MDVSA-2008:171
RHSA-2008:0839
SUSE-SA:2008:040
USN-636-1
VU#938323
http://article.gmane.org/gmane.mail.postfix.announce/110
ftp://ftp.porcupine.org/mirrors/postfix-release/experimental/postfix-2.6-20080814.HISTORY
ftp://ftp.porcupine.org/mirrors/postfix-release/official/postfix-2.3.15.HISTORY
ftp://ftp.porcupine.org/mirrors/postfix-release/official/postfix-2.4.8.HISTORY
ftp://ftp.porcupine.org/mirrors/postfix-release/official/postfix-2.5.4.HISTORY
http://wiki.rpath.com/Advisories:rPSA-2008-0259
https://issues.rpath.com/browse/RPL-2689
oval:org.mitre.oval:def:10033
postfix-symlink-code-execution(44460)

CPE    28
cpe:/a:postfix:postfix:2.5.1
cpe:/a:postfix:postfix:2.6.0
cpe:/a:postfix:postfix:2.3.3
cpe:/a:postfix:postfix:2.4.2
...
CWE    1
CWE-264
OVAL    2
oval:org.secpod.oval:def:301583
oval:org.mitre.oval:def:7819

© SecPod Technologies