CVE-2009-2939
Debian Security Advisory 2233-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.
El script postfix.postinst en el paquete postfix v2.5.5 de Debian GNU/Linux y Ubuntu permite acceso de escritura al usuario postfix en /var/spool/postfix/pid, permitiendo a usuarios locales dirigir ataques de enlaces simbólicos que sobrescriban ficheros de su elección.
It was discovered that the Postfix package incorrectly granted write access on the PID directory to the postfix user. A local attacker could use this flaw to possibly conduct a symlink attack and overwrite arbitrary files. This issue only affected Ubuntu 6.06 LTS and 8.04 LTS. Wietse Venema discovered that Postfix incorrectly handled cleartext commands after TLS is in place. A remote attacker could exploit this to inject cleartext commands into TLS sessions, and possibly obtain confidential information such as passwords.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-08-23 CVE Reserved
- 2009-09-21 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-59: Improper Link Resolution Before File Access ('Link Following')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
http://www.openwall.com/lists/oss-security/2009/09/18/6 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2011/dsa-2233 | 2011-08-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Postfix Search vendor "Postfix" | Postfix Search vendor "Postfix" for product "Postfix" | 2.5.5 Search vendor "Postfix" for product "Postfix" and version "2.5.5" | - |
Affected
| in | Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 6.06 Search vendor "Debian" for product "Debian Linux" and version "6.06" | - |
Safe
|
Postfix Search vendor "Postfix" | Postfix Search vendor "Postfix" for product "Postfix" | 2.5.5 Search vendor "Postfix" for product "Postfix" and version "2.5.5" | - |
Affected
| in | Ubuntu Search vendor "Ubuntu" | Ubuntu Linux Search vendor "Ubuntu" for product "Ubuntu Linux" | 4.0 Search vendor "Ubuntu" for product "Ubuntu Linux" and version "4.0" | - |
Safe
|