postfix: multiple vulnerabilities
Package(s): | postfix |
CVE #(s): | CVE-2008-2936
CVE-2008-2937
|
Created: | August 14, 2008 |
Updated: | April 15, 2011 |
Description: |
The postfix MTA has two vulnerabilities. From the SuSE alert:
During a source code audit the SuSE Security-Team discovered a local
privilege escalation bug (CVE-2008-2936) as well as a mailbox ownership
problem (CVE-2008-2937) in postfix.
The first bug allowed local users to execute arbitrary commands as root
while the second one allowed local users to read other users mail. |
Alerts: |
|