Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-2939

Опубликовано: 21 сент. 2009
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS2: 6.9

Описание

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.

РелизСтатусПримечание
dapper

released

2.2.10-1ubuntu0.3
devel

released

2.6.5-3
hardy

released

2.5.1-2ubuntu1.3
intrepid

ignored

end of life, was needed
jaunty

ignored

end of life
karmic

released

2.6.5-3
lucid

released

2.6.5-3
maverick

released

2.6.5-3
upstream

released

2.6.5-3

Показывать по

EPSS

Процентиль: 5%
0.00024
Низкий

6.9 Medium

CVSS2

Связанные уязвимости

nvd
больше 15 лет назад

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.

debian
больше 15 лет назад

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix ...

github
около 3 лет назад

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.

EPSS

Процентиль: 5%
0.00024
Низкий

6.9 Medium

CVSS2