Sploitus

CVE-2008-2936

6 known exploits for CVE-2008-2936

Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message. NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.

Affected products
Postfix, Red Hat
Postfix
= 2.3.0, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 2.3.6, 2.3.7, 2.3.8, 2.3.9, 2.3.10, 2.3.11, 2.3.12, 2.3.13, 2.3.14, 2.4.0, 2.4.1, 2.4.2, 2.4.3, 2.4.4, 2.4.5, 2.4.6, 2.4.7, 2.5.0, 2.5.1, 2.5.2, 2.5.3, 2.6.0
Fix
Available
CVSS 2.0
6.2 MEDIUM
EPSS
1.0% (60th percentile)
Weakness
CWE-264
NVD status
Modified
Published
2008-08-18
CVE-2008-2936 at NVD
Authoritative description, scoring and affected products

6 known exploits for CVE-2008-2936

Proof-of-concept code and exploit modules indexed by Sploitus