Lucene search

K
prionPRIOn knowledge basePRION:CVE-2009-2939
HistorySep 21, 2009 - 7:30 p.m.

Code injection

2009-09-2119:30:00
PRIOn knowledge base
www.prio-n.com
8

6.7 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.

CPENameOperatorVersion
postfixeq2.5.5

6.7 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%