Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which allows local users to read e-mail messages by creating a mailbox file corresponding to another user's account name.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade postfix-pflogsummUpgrade postfix | Dec 1, 2016 | Aug 18, 2008 |
| Debian | — | Upgrade postfix | Jul 30, 2024 | Aug 18, 2008 |
| Gentoo Linux | — | Upgrade mail-mta/postfix. | Oct 30, 2017 | Aug 18, 2008 |
| Oracle_linux | — | Upgrade postfix-pflogsummUpgrade postfix | Oct 16, 2024 | Aug 18, 2008 |
| Postfix | — | Upgrade to the latest version of Postfix | Jul 3, 2014 | Aug 18, 2008 |
| Suse | — | Upgrade postfix-develUpgrade postfixUpgrade postfix-postgresqlUpgrade postfix-mysqlUpgrade suse-release | Feb 17, 2015 | Aug 18, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub