vendor:
Postfix
by:
Roman Medina-Heigl Hernandez
7.2
CVSS
HIGH
Local Privilege Escalation
264
CWE
Product Name: Postfix
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2008-2936
CPE: postfix
Metasploit:
https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2008-2936/, https://www.rapid7.com/db/vulnerabilities/postfix-cve-2008-2936/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2008-2936/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2008-2936/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2008-0839/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu, Debian
2008
Postfix local root vulnerability: CVE-2008-2936
This PoC exploits a local privilege escalation vulnerability in Postfix. It creates a hardlink to a symlink, which is not dereferenced, and then creates an alias in the alias maps. It then sends a mail to the root user, which is then used to modify the /etc/passwd file.
Mitigation:
Upgrade to the latest version of Postfix, or apply the patch provided by the vendor.