Vulnerability Name: | CVE-2008-4977 | ||||||||
Assigned: | 2008-11-06 | ||||||||
Published: | 2008-11-06 | ||||||||
Updated: | 2008-11-06 | ||||||||
Summary: | ** DISPUTED ** postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdout, (2) /tmp/postfix_groups.stderr, and (3) /tmp/postfix_groups.message temporary files. Note: the vendor disputes this vulnerability, stating "This is not a real issue ... users would have to edit a script under /usr/lib to enable it." | ||||||||
CVSS v3 Severity: | 8.1 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-59 | ||||||||
References: | Source: MISC Type: UNKNOWN http://bugs.debian.org/496401 Source: MITRE Type: CNA CVE-2008-4977 Source: MISC Type: Exploit http://dev.gentoo.org/~rbu/security/debiantemp/postfix Source: MLIST Type: UNKNOWN [oss-security] 20081030 CVE requests: tempfile issues for aview, mgetty, openoffice, crossfire Source: MISC Type: UNKNOWN https://bugs.gentoo.org/show_bug.cgi?id=235770 Source: MISC Type: UNKNOWN https://bugs.gentoo.org/show_bug.cgi?id=235811 | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |