postfix privilege escalation flaw
Published Aug 18, 2008
6.2
MEDIUMCVSS 2.0
EPSS 0.99%
Description
Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message. NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.
Affected products
No data.
- 2.3.0
- 2.3.1
- 2.3.2
- 2.3.3
- 2.3.4
- 2.3.5
- 2.3.6
- 2.3.7
- 2.3.8
- 2.3.9
- 2.3.10
- 2.3.11
- 2.3.12
- 2.3.13
- 2.3.14
- 2.4.0
- 2.4.1
- 2.4.2
- 2.4.3
- 2.4.4
- 2.4.5
- 2.4.6
- 2.4.7
- 2.5.0
- 2.5.1
- 2.5.2
- 2.5.3
- 2.6.0
No data.
Red Hat Enterprise Linux 3
postfix-2:2.0.16-14.1.RHEL3
Fixed · RHSA-2008:0839
Red Hat Enterprise Linux 4
postfix-2:2.2.10-1.2.1.el4_7
Fixed · RHSA-2008:0839
Red Hat Enterprise Linux 5
postfix-2:2.3.3-2.1.el5_2
Fixed · RHSA-2008:0839
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | postfix-2:2.0.16-14.1.RHEL3 | Fixed | RHSA-2008:0839 |
| Red Hat Enterprise Linux 4 | postfix-2:2.2.10-1.2.1.el4_7 | Fixed | RHSA-2008:0839 |
| Red Hat Enterprise Linux 5 | postfix-2:2.3.3-2.1.el5_2 | Fixed | RHSA-2008:0839 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:H/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.99% (0.00993) | 61.23th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.00% (0.01001) | 58.15th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.26% (0.00264) | 47.80th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00048) | 19.90th | v3 (v2023.03.01) |
| May 18, 2024 | 0.05% (0.00048) | 17.26th | v3 (v2023.03.01) |
| Oct 8, 2023 | 0.05% (0.00048) | 15.21th | v3 (v2023.03.01) |
| Jul 26, 2023 | 0.06% (0.00057) | 21.79th | v3 (v2023.03.01) |
| May 9, 2023 | 0.05% (0.00048) | 15.16th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 0.50th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.22% (0.03220) | 84.21th | v2 (v2022.01.01) |
| Feb 13, 2023 | 3.22% (0.03220) | 83.79th | v2 (v2022.01.01) |
| Feb 3, 2023 | 5.79% (0.05787) | 90.14th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.22% (0.03220) | 82.61th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.22% (0.03220) | 65.30th | v2 (v2022.01.01) |
References (37)
- ftp://ftp.porcupine.org/mirrors/postfix-release/experimental/postfix-2.6-20080814.HISTORY x_refsource_CONFIRM
- ftp://ftp.porcupine.org/mirrors/postfix-release/official/postfix-2.3.15.HISTORY x_refsource_CONFIRM
- ftp://ftp.porcupine.org/mirrors/postfix-release/official/postfix-2.4.8.HISTORY x_refsource_CONFIRM
- ftp://ftp.porcupine.org/mirrors/postfix-release/official/postfix-2.5.4.HISTORY x_refsource_CONFIRM
- http://article.gmane.org/gmane.mail.postfix.announce/110 mailing-listx_refsource_MLIST
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00002.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/31469 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31474 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31477 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31485 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31500 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31530 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/32231 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200808-12.xml vendor-advisoryx_refsource_GENTOO
- http://securityreason.com/securityalert/4160 third-party-advisoryx_refsource_SREASON
- http://wiki.rpath.com/Advisories:rPSA-2008-0259 x_refsource_CONFIRM
- http://www.debian.org/security/2008/dsa-1629 vendor-advisoryx_refsource_DEBIAN
- http://www.kb.cert.org/vuls/id/938323 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:171 vendor-advisoryx_refsource_MANDRIVA
- http://www.redhat.com/support/errata/RHSA-2008-0839.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/495474/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/495632/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/495882/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/30691 vdb-entryx_refsource_BIDPatch
- http://www.securitytracker.com/id?1020700 vdb-entryx_refsource_SECTRACK
- http://www.vupen.com/english/advisories/2008/2385 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2008-2936 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=456314 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44460 vdb-entryx_refsource_XF
- https://issues.rpath.com/browse/RPL-2689 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2008-2936
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10033 vdb-entrysignaturex_refsource_OVAL
- https://usn.ubuntu.com/636-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2008-2936
- https://www.exploit-db.com/exploits/6337 exploitx_refsource_EXPLOIT-DB
- https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00271.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00287.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.