6.9
CVSSv2

CVE-2009-2939

Published: 21/09/2009 Updated: 24/08/2011
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.

Vulnerable Product Search on Vulmon Subscribe to Product

postfix postfix 2.5.5

Vendor Advisories

An attacker could send crafted input to Postfix and cause it to reveal confidential information ...
Several vulnerabilities were discovered in Postfix, a mail transfer agent The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-2939 The postinst script grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwr ...