postfix-2.3.3-2.9AXS3
エラータID: AXSA:2008-88:01
Release date:
Monday, September 22, 2008 - 12:53
Subject:
postfix-2.3.3-2.9AXS3
Affected Channels:
Asianux Server 3 for x86_64
Asianux Server 3 for ppc
Asianux Server 3 for ia64
Asianux Server 3 for x86
Severity:
High
Description:
Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL),
and TLS.
CVE-2008-2936:
Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message.
NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.
Solution:
Update packages
CVEs:
CVE-2008-2936
Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message. NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.
Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message. NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.
Additional Info:
N/A
Download:
Asianux Server 3 for x86
- postfix-2.3.3-2.9AXS3.i386.rpm
MD5: 491f2862c1a95f8f80b343fef39f7f25
SHA-256: 77a5d73da9957e9bcf8a38b97a6014c360fe100f354013bccd6727baaa187a7b
Size: 3.71 MB - postfix-pflogsumm-2.3.3-2.9AXS3.i386.rpm
MD5: ee1f945ce5102e0940746fb18e857b35
SHA-256: cbac8f1b9b8fa3dd766013c1808f30b060118299b6c848d52cb9f57fa3726d9a
Size: 50.39 kB
Asianux Server 3 for x86_64
- postfix-2.3.3-2.9AXS3.x86_64.rpm
MD5: 957159cd1ea941827fe0922e7704cb03
SHA-256: 5d4a1fae09a39dbc15eb8d9c5bda4a32767d7a9c9c1829cd4afab62fd5da7848
Size: 3.84 MB - postfix-pflogsumm-2.3.3-2.9AXS3.x86_64.rpm
MD5: 31c16044a64a4677bfa7194cbb998f82
SHA-256: aa1f5d4682da72de0214570b54526670d1e9215b03fb7a97b5d3ccc671053765
Size: 49.98 kB