SB2008081401 - Gentoo update for Postfix
Published: August 14, 2008 Updated: June 28, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) UNIX Hard Link (CVE-ID: CVE-2008-2936)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to an error when following hard links. A local user can append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then send the message.
2) Information disclosure (CVE-ID: CVE-2008-2937)
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to software delivers to a mailbox file even when this file is not owned by the recipient. A local user can read e-mail messages by creating a mailbox file corresponding to another user's account name.
Remediation
Install update from vendor's website.