6.2

CVE-2008-2936

Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message.  NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PostfixPostfix Version2.3.0
PostfixPostfix Version2.3.1
PostfixPostfix Version2.3.2
PostfixPostfix Version2.3.3
PostfixPostfix Version2.3.4
PostfixPostfix Version2.3.5
PostfixPostfix Version2.3.6
PostfixPostfix Version2.3.7
PostfixPostfix Version2.3.8
PostfixPostfix Version2.3.9
PostfixPostfix Version2.3.10
PostfixPostfix Version2.3.11
PostfixPostfix Version2.3.12
PostfixPostfix Version2.3.13
PostfixPostfix Version2.3.14
PostfixPostfix Version2.4.0
PostfixPostfix Version2.4.1
PostfixPostfix Version2.4.2
PostfixPostfix Version2.4.3
PostfixPostfix Version2.4.4
PostfixPostfix Version2.4.5
PostfixPostfix Version2.4.6
PostfixPostfix Version2.4.7
PostfixPostfix Version2.5.0
PostfixPostfix Version2.5.1
PostfixPostfix Version2.5.2
PostfixPostfix Version2.5.3
PostfixPostfix Version2.6.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.521
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.2 1.9 10
AV:L/AC:H/Au:N/C:C/I:C/A:C