Логотип exploitDog
product: "postfix"
Консоль
Логотип exploitDog

exploitDog

product: "postfix"
postfix

postfixагент передачи почты (MTA — mail transfer agent).

Релизный цикл, информация об уязвимостях

Продукт: postfix
Вендор: postfix

График релизов

3.53.63.73.83.93.102020202120222023202420252026

Недавние уязвимости postfix

Количество 71

redhat логотип

CVE-2011-0411

больше 14 лет назад

The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.

CVSS2: 4
EPSS: Средний
nvd логотип

CVE-2009-2939

больше 15 лет назад

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.

CVSS2: 6.9
EPSS: Низкий
debian логотип

CVE-2009-2939

больше 15 лет назад

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix ...

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2009-2939

больше 15 лет назад

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.

CVSS2: 6.9
EPSS: Низкий
nvd логотип

CVE-2008-4977

больше 16 лет назад

postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdout, (2) /tmp/postfix_groups.stderr, and (3) /tmp/postfix_groups.message temporary files. NOTE: the vendor disputes this vulnerability, stating "This is not a real issue ... users would have to edit a script under /usr/lib to enable it.

CVSS2: 6.9
EPSS: Низкий
debian логотип

CVE-2008-4977

больше 16 лет назад

postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arb ...

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2008-4977

больше 16 лет назад

** DISPUTED ** postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdout, (2) /tmp/postfix_groups.stderr, and (3) /tmp/postfix_groups.message temporary files. NOTE: the vendor disputes this vulnerability, stating "This is not a real issue ... users would have to edit a script under /usr/lib to enable it."

CVSS2: 6.9
EPSS: Низкий
nvd логотип

CVE-2008-3889

почти 17 лет назад

Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors during execution of "non-Postfix" commands, which allows local users to cause a denial of service (application slowdown or exit) via a crafted command, as demonstrated by a command in a .forward file.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2008-3889

почти 17 лет назад

Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-2008090 ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2008-3889

почти 17 лет назад

Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors during execution of "non-Postfix" commands, which allows local users to cause a denial of service (application slowdown or exit) via a crafted command, as demonstrated by a command in a .forward file.

CVSS2: 2.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2011-0411

The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.

CVSS2: 4
69%
Средний
больше 14 лет назад
nvd логотип
CVE-2009-2939

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.

CVSS2: 6.9
0%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-2939

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix ...

CVSS2: 6.9
0%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2009-2939

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.

CVSS2: 6.9
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2008-4977

postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdout, (2) /tmp/postfix_groups.stderr, and (3) /tmp/postfix_groups.message temporary files. NOTE: the vendor disputes this vulnerability, stating "This is not a real issue ... users would have to edit a script under /usr/lib to enable it.

CVSS2: 6.9
0%
Низкий
больше 16 лет назад
debian логотип
CVE-2008-4977

postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arb ...

CVSS2: 6.9
0%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2008-4977

** DISPUTED ** postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdout, (2) /tmp/postfix_groups.stderr, and (3) /tmp/postfix_groups.message temporary files. NOTE: the vendor disputes this vulnerability, stating "This is not a real issue ... users would have to edit a script under /usr/lib to enable it."

CVSS2: 6.9
0%
Низкий
больше 16 лет назад
nvd логотип
CVE-2008-3889

Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors during execution of "non-Postfix" commands, which allows local users to cause a denial of service (application slowdown or exit) via a crafted command, as demonstrated by a command in a .forward file.

CVSS2: 2.1
0%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-3889

Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-2008090 ...

CVSS2: 2.1
0%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-3889

Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors during execution of "non-Postfix" commands, which allows local users to cause a denial of service (application slowdown or exit) via a crafted command, as demonstrated by a command in a .forward file.

CVSS2: 2.1
0%
Низкий
почти 17 лет назад

Уязвимостей на страницу


Поделиться