Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

postfix

postfixагент передачи почты (MTA — mail transfer agent).

Релизный цикл, информация об уязвимостях

Продукт: postfix
Вендор: postfix

График релизов

3.63.73.83.93.103.112021202220232024202520262027

Релизные элементы

KBВерсияБилдДата доступности
3.10.143.10.14
3.10.133.10.13
3.10.123.10.12
3.10.113.10.11
3.10.103.10.10
3.10.93.10.9
3.10.83.10.8
3.10.73.10.7
3.10.63.10.6
3.10.53.10.5

Показывать по

Недавние уязвимости postfix

Количество 91

debian логотип

CVE-2009-2939

почти 17 лет назад

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix ...

CVSS2: 6.9
EPSS: Низкий
nvd логотип

CVE-2009-2939

почти 17 лет назад

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2009-2939

почти 17 лет назад

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.

CVSS2: 6.9
EPSS: Низкий
debian логотип

CVE-2008-4977

почти 18 лет назад

postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arb ...

CVSS2: 6.9
EPSS: Низкий
nvd логотип

CVE-2008-4977

почти 18 лет назад

postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdout, (2) /tmp/postfix_groups.stderr, and (3) /tmp/postfix_groups.message temporary files. NOTE: the vendor disputes this vulnerability, stating "This is not a real issue ... users would have to edit a script under /usr/lib to enable it.

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2008-4977

почти 18 лет назад

postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdout, (2) /tmp/postfix_groups.stderr, and (3) /tmp/postfix_groups.message temporary files. NOTE: the vendor disputes this vulnerability, stating "This is not a real issue ... users would have to edit a script under /usr/lib to enable it.

CVSS2: 6.9
EPSS: Низкий
debian логотип

CVE-2008-3889

около 18 лет назад

Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-2008090 ...

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2008-3889

около 18 лет назад

Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors during execution of "non-Postfix" commands, which allows local users to cause a denial of service (application slowdown or exit) via a crafted command, as demonstrated by a command in a .forward file.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2008-3889

около 18 лет назад

Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors during execution of "non-Postfix" commands, which allows local users to cause a denial of service (application slowdown or exit) via a crafted command, as demonstrated by a command in a .forward file.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2008-3889

около 18 лет назад

Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors during execution of "non-Postfix" commands, which allows local users to cause a denial of service (application slowdown or exit) via a crafted command, as demonstrated by a command in a .forward file.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2009-2939

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix ...

CVSS2: 6.9
0%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-2939

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.

CVSS2: 6.9
0%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2009-2939

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.

CVSS2: 6.9
0%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-4977

postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arb ...

CVSS2: 6.9
0%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4977

postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdout, (2) /tmp/postfix_groups.stderr, and (3) /tmp/postfix_groups.message temporary files. NOTE: the vendor disputes this vulnerability, stating "This is not a real issue ... users would have to edit a script under /usr/lib to enable it.

CVSS2: 6.9
0%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-4977

postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdout, (2) /tmp/postfix_groups.stderr, and (3) /tmp/postfix_groups.message temporary files. NOTE: the vendor disputes this vulnerability, stating "This is not a real issue ... users would have to edit a script under /usr/lib to enable it.

CVSS2: 6.9
0%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-3889

Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-2008090 ...

CVSS2: 2.1
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3889

Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors during execution of "non-Postfix" commands, which allows local users to cause a denial of service (application slowdown or exit) via a crafted command, as demonstrated by a command in a .forward file.

CVSS2: 2.1
1%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2008-3889

Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors during execution of "non-Postfix" commands, which allows local users to cause a denial of service (application slowdown or exit) via a crafted command, as demonstrated by a command in a .forward file.

CVSS2: 2.1
1%
Низкий
около 18 лет назад
redhat логотип
CVE-2008-3889

Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors during execution of "non-Postfix" commands, which allows local users to cause a denial of service (application slowdown or exit) via a crafted command, as demonstrated by a command in a .forward file.

1%
Низкий
около 18 лет назад

Уязвимостей на страницу


Поделиться