Lucene search

K
cveRedhatCVE-2008-2936
HistoryAug 18, 2008 - 7:41 p.m.

CVE-2008-2936

2008-08-1819:41:00
CWE-264
redhat
web.nvd.nist.gov
52
postfix
cve-2008-2936
symlink vulnerability
email security
nvd

CVSS2

6.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:C/I:C/A:C

AI Score

6

Confidence

Low

EPSS

0.001

Percentile

17.9%

Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message. NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.

Affected configurations

Nvd
Node
postfixpostfixMatch2.3.0
OR
postfixpostfixMatch2.3.1
OR
postfixpostfixMatch2.3.2
OR
postfixpostfixMatch2.3.3
OR
postfixpostfixMatch2.3.4
OR
postfixpostfixMatch2.3.5
OR
postfixpostfixMatch2.3.6
OR
postfixpostfixMatch2.3.7
OR
postfixpostfixMatch2.3.8
OR
postfixpostfixMatch2.3.9
OR
postfixpostfixMatch2.3.10
OR
postfixpostfixMatch2.3.11
OR
postfixpostfixMatch2.3.12
OR
postfixpostfixMatch2.3.13
OR
postfixpostfixMatch2.3.14
OR
postfixpostfixMatch2.4.0
OR
postfixpostfixMatch2.4.1
OR
postfixpostfixMatch2.4.2
OR
postfixpostfixMatch2.4.3
OR
postfixpostfixMatch2.4.4
OR
postfixpostfixMatch2.4.5
OR
postfixpostfixMatch2.4.6
OR
postfixpostfixMatch2.4.7
OR
postfixpostfixMatch2.5.0
OR
postfixpostfixMatch2.5.1
OR
postfixpostfixMatch2.5.2
OR
postfixpostfixMatch2.5.3
OR
postfixpostfixMatch2.6.0
VendorProductVersionCPE
postfixpostfix2.3.0cpe:2.3:a:postfix:postfix:2.3.0:*:*:*:*:*:*:*
postfixpostfix2.3.1cpe:2.3:a:postfix:postfix:2.3.1:*:*:*:*:*:*:*
postfixpostfix2.3.2cpe:2.3:a:postfix:postfix:2.3.2:*:*:*:*:*:*:*
postfixpostfix2.3.3cpe:2.3:a:postfix:postfix:2.3.3:*:*:*:*:*:*:*
postfixpostfix2.3.4cpe:2.3:a:postfix:postfix:2.3.4:*:*:*:*:*:*:*
postfixpostfix2.3.5cpe:2.3:a:postfix:postfix:2.3.5:*:*:*:*:*:*:*
postfixpostfix2.3.6cpe:2.3:a:postfix:postfix:2.3.6:*:*:*:*:*:*:*
postfixpostfix2.3.7cpe:2.3:a:postfix:postfix:2.3.7:*:*:*:*:*:*:*
postfixpostfix2.3.8cpe:2.3:a:postfix:postfix:2.3.8:*:*:*:*:*:*:*
postfixpostfix2.3.9cpe:2.3:a:postfix:postfix:2.3.9:*:*:*:*:*:*:*
Rows per page:
1-10 of 281

References

CVSS2

6.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:C/I:C/A:C

AI Score

6

Confidence

Low

EPSS

0.001

Percentile

17.9%