CVE-2008-2937

Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which allows local users to read e-mail messages by creating a mailbox file corresponding to another user's account name.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:postfix:postfix:2.5.2:*:*:*:*:*:*:*
cpe:2.3:a:postfix:postfix:2.5.3:*:*:*:*:*:*:*
cpe:2.3:a:postfix:postfix:2.6.0:*:*:*:*:*:*:*
cpe:2.3:a:postfix:postfix:2.5.0:*:*:*:*:*:*:*
cpe:2.3:a:postfix:postfix:2.5.1:*:*:*:*:*:*:*

Information

Published : 2008-08-18 12:41

Updated : 2018-10-11 13:45


NVD link : CVE-2008-2937

Mitre link : CVE-2008-2937


JSON object : View

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

Advertisement

dedicated server usa

Products Affected

postfix

  • postfix