Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rpqw-5g6j-x944

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.

EPSS

Процентиль: 5%
0.00024
Низкий

Дефекты

CWE-59

Связанные уязвимости

ubuntu
больше 15 лет назад

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.

nvd
больше 15 лет назад

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.

debian
больше 15 лет назад

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix ...

EPSS

Процентиль: 5%
0.00024
Низкий

Дефекты

CWE-59