VDB
DEBIAN-CVE-2008-2936
DEBIAN-CVE-2008-2936
PUBLISHED
Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message. NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:12 | postfix | 0, 0, 0 |
| Debian:13 | postfix | 0, 0, 0 |
| Debian:14 | postfix | 0, 0, 0 |
| Debian:11 | postfix | 0, 0, 0 |
Timeline
- Aug 18, 2008 CVE Published
- Apr 28, 2026 CVE Updated