Postfix 2.5 prior to 2.5.4 and 2.6 prior to 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which allows local users to read e-mail messages by creating a mailbox file corresponding to another user's account name.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
postfix postfix 2.5.2 |
||
postfix postfix 2.5.3 |
||
postfix postfix 2.6.0 |
||
postfix postfix 2.5.0 |
||
postfix postfix 2.5.1 |