CVE-2008-2936
published 2008-08-18CVE-2008-2936: Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local…
PriorityP425medium6.2CVSS 2.0
AVLACHAuNCCICAC
EXPLOIT
EPSS
1.00%
58.5th percentile
Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message. NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | postfix | < postfix 2.5.4-1 (bookworm) | postfix 2.5.4-1 (bookworm) |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
| postfix | postfix | — | — |
CVSS provenance
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
osv6.2MEDIUM
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Postfix vulnerability
vendor_ubuntu·2008-08-19
CVE-2008-2936 Postfix vulnerability
Title: Postfix vulnerability
Summary: Postfix vulnerability
Sebastian Krahmer discovered that Postfix was not correctly handling
mailbox ownership when dealing with Linux's implementation of hardlinking
to symlinks. In certain mail spool configurations, a local attacker
could exploit this to append data to arbitrary files as the root user.
The default Ubuntu configuration was not vulnerable.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
postfix privilege escalation flaw
vendor_redhat·2008-08-14·CVSS 6.2
CVE-2008-2936 [MEDIUM] postfix privilege escalation flaw
postfix privilege escalation flaw
Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message. NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.
Debian
CVE-2008-2936: postfix - Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20...
vendor_debian·2008·CVSS 6.2
CVE-2008-2936 [MEDIUM] CVE-2008-2936: postfix - Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20...
Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message. NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.
Scope: local
bookworm: resolved (fixed in 2.5.4-1)
bullseye: resolved (fixed in 2.5.4-1)
forky: resolved (fixed in 2.5.4-1)
sid: resolved (fixed in 2.5.4-1)
trixie: resolved (fixed in 2.5.4-1)
GHSA
GHSA-8739-vxjm-m9p4: Postfix before 2
ghsa_unreviewed·2022-05-03
CVE-2008-2936 [MEDIUM] GHSA-8739-vxjm-m9p4: Postfix before 2
Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message. NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.
OSV
CVE-2008-2936: Postfix before 2
osv·2008-08-18·CVSS 6.2
CVE-2008-2936 [MEDIUM] CVE-2008-2936: Postfix before 2
Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message. NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.
No detection rules found.
ftp://ftp.porcupine.org/mirrors/postfix-release/experimental/postfix-2.6-20080814.HISTORYftp://ftp.porcupine.org/mirrors/postfix-release/official/postfix-2.3.15.HISTORYftp://ftp.porcupine.org/mirrors/postfix-release/official/postfix-2.4.8.HISTORYftp://ftp.porcupine.org/mirrors/postfix-release/official/postfix-2.5.4.HISTORYhttp://article.gmane.org/gmane.mail.postfix.announce/110http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00002.htmlhttp://secunia.com/advisories/31469http://secunia.com/advisories/31474http://secunia.com/advisories/31477http://secunia.com/advisories/31485http://secunia.com/advisories/31500http://secunia.com/advisories/31530http://secunia.com/advisories/32231http://security.gentoo.org/glsa/glsa-200808-12.xmlhttp://securityreason.com/securityalert/4160http://wiki.rpath.com/Advisories:rPSA-2008-0259http://www.debian.org/security/2008/dsa-1629http://www.kb.cert.org/vuls/id/938323http://www.mandriva.com/security/advisories?name=MDVSA-2008:171http://www.redhat.com/support/errata/RHSA-2008-0839.htmlhttp://www.securityfocus.com/archive/1/495474/100/0/threadedhttp://www.securityfocus.com/archive/1/495632/100/0/threadedhttp://www.securityfocus.com/archive/1/495882/100/0/threadedhttp://www.securityfocus.com/bid/30691http://www.securitytracker.com/id?1020700http://www.vupen.com/english/advisories/2008/2385https://exchange.xforce.ibmcloud.com/vulnerabilities/44460https://issues.rpath.com/browse/RPL-2689https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10033https://usn.ubuntu.com/636-1/https://www.exploit-db.com/exploits/6337https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00271.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-October/msg00287.htmlftp://ftp.porcupine.org/mirrors/postfix-release/experimental/postfix-2.6-20080814.HISTORYftp://ftp.porcupine.org/mirrors/postfix-release/official/postfix-2.3.15.HISTORYftp://ftp.porcupine.org/mirrors/postfix-release/official/postfix-2.4.8.HISTORYftp://ftp.porcupine.org/mirrors/postfix-release/official/postfix-2.5.4.HISTORYhttp://article.gmane.org/gmane.mail.postfix.announce/110http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00002.htmlhttp://secunia.com/advisories/31469http://secunia.com/advisories/31474http://secunia.com/advisories/31477http://secunia.com/advisories/31485http://secunia.com/advisories/31500http://secunia.com/advisories/31530http://secunia.com/advisories/32231http://security.gentoo.org/glsa/glsa-200808-12.xmlhttp://securityreason.com/securityalert/4160http://wiki.rpath.com/Advisories:rPSA-2008-0259http://www.debian.org/security/2008/dsa-1629http://www.kb.cert.org/vuls/id/938323http://www.mandriva.com/security/advisories?name=MDVSA-2008:171http://www.redhat.com/support/errata/RHSA-2008-0839.htmlhttp://www.securityfocus.com/archive/1/495474/100/0/threadedhttp://www.securityfocus.com/archive/1/495632/100/0/threadedhttp://www.securityfocus.com/archive/1/495882/100/0/threadedhttp://www.securityfocus.com/bid/30691http://www.securitytracker.com/id?1020700http://www.vupen.com/english/advisories/2008/2385https://exchange.xforce.ibmcloud.com/vulnerabilities/44460https://issues.rpath.com/browse/RPL-2689https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10033https://usn.ubuntu.com/636-1/https://www.exploit-db.com/exploits/6337https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00271.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-October/msg00287.html
2008-08-18
Published