PT-2008-4374 · Postfix+1 · Postfix+1

Publicado

2008-08-18

·

Atualizado

2018-10-11

·

CVE-2008-2937

CVSS v2.0

1.9

Baixa

VetorAV:L/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Postfix versions 2.5 through 2.5.3 Postfix versions 2.6 through 2.6-20080813
Description The issue allows local users to read e-mail messages by creating a mailbox file corresponding to another user's account name, because Postfix delivers to a mailbox file even when this file is not owned by the recipient.
Recommendations For Postfix versions 2.5 through 2.5.3, update to version 2.5.4 or later. For Postfix versions 2.6 through 2.6-20080813, update to version 2.6-20080814 or later.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-2937
RHSA-2011:0422
RHSA-2011_0422

Produtos afetados

Postfix
Red Hat