Back to search
CVE-2008-2936
Published: Aug 18, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message. NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2008-8595
vendor-advisory
x_refsource_FEDORA
32231
third-party-advisory
x_refsource_SECUNIA
31469
third-party-advisory
x_refsource_SECUNIA
DSA-1629
vendor-advisory
x_refsource_DEBIAN
31530
third-party-advisory
x_refsource_SECUNIA
FEDORA-2008-8593
vendor-advisory
x_refsource_FEDORA
https://issues.rpath.com/browse/RPL-2689
x_refsource_CONFIRM
1020700
vdb-entry
x_refsource_SECTRACK
20080821 rPSA-2008-0259-1 postfix
mailing-list
x_refsource_BUGTRAQ
VU#938323
third-party-advisory
x_refsource_CERT-VN
[postfix-announce] 20080814 Postfix local privilege escalation via hardlinked symlinks
mailing-list
x_refsource_MLIST
4160
third-party-advisory
x_refsource_SREASON
30691
vdb-entry
x_refsource_BID
http://wiki.rpath.com/Advisories:rPSA-2008-0259
x_refsource_CONFIRM
SUSE-SA:2008:040
vendor-advisory
x_refsource_SUSE
31474
third-party-advisory
x_refsource_SECUNIA
20080831 PoCfix (PoC for Postfix local root vuln - CVE-2008-2936)
mailing-list
x_refsource_BUGTRAQ
postfix-symlink-code-execution(44460)
vdb-entry
x_refsource_XF
6337
exploit
x_refsource_EXPLOIT-DB
RHSA-2008:0839
vendor-advisory
x_refsource_REDHAT
31500
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:10033
vdb-entry
signature
x_refsource_OVAL
31477
third-party-advisory
x_refsource_SECUNIA
31485
third-party-advisory
x_refsource_SECUNIA
USN-636-1
vendor-advisory
x_refsource_UBUNTU
MDVSA-2008:171
vendor-advisory
x_refsource_MANDRIVA
20080814 Postfix local privilege escalation via hardlinked symlinks
mailing-list
x_refsource_BUGTRAQ
ADV-2008-2385
vdb-entry
x_refsource_VUPEN
GLSA-200808-12
vendor-advisory
x_refsource_GENTOO
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now