Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24528
HistoryApr 10, 2020 - 12:56 a.m.

Information Disclosure

2020-04-1000:56:27
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.0004 Low

EPSS

Percentile

10.1%

postfix is vulnerable to information disclosure. It was discovered that Postfix did not properly check the permissions of users’ mailbox files. A local attacker able to create files in the mail spool directory could use this flaw to create mailbox files for other local users, and be able to read mail delivered to those users.

References