LWN.net Logo

postfix: multiple vulnerabilities

Package(s):postfix CVE #(s):CVE-2008-2936 CVE-2008-2937
Created:August 14, 2008 Updated:April 15, 2011
Description: The postfix MTA has two vulnerabilities. From the SuSE alert: During a source code audit the SuSE Security-Team discovered a local privilege escalation bug (CVE-2008-2936) as well as a mailbox ownership problem (CVE-2008-2937) in postfix. The first bug allowed local users to execute arbitrary commands as root while the second one allowed local users to read other users mail.
Alerts:
CentOS CESA-2011:0422 2011-04-14
CentOS CESA-2011:0422 2011-04-08
Red Hat RHSA-2011:0422-01 2011-04-06
Mandriva MDVSA-2009:224-1 2009-12-04
Mandriva MDVSA-2009:224 2009-08-30
rPath rPSA-2008-0294-1 2008-10-16
Fedora FEDORA-2008-8595 2008-10-09
Fedora FEDORA-2008-8593 2008-10-09
Ubuntu USN-636-1 2008-08-19
Mandriva MDVSA-2008:171 2007-08-15
CentOS CESA-2008:0839 2008-08-15
Debian DSA-1629-2 2008-08-19
Debian DSA-1629-1 2008-08-18
Red Hat RHSA-2008:0839-01 2008-08-14
rPath rPSA-2008-0259-1 2008-08-20
Gentoo 200808-12 2008-08-14
SuSE SUSE-SA:2008:040 2008-08-14

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds