acknowledge the elephant in the room
Showing 1 - 1 of 1 RSS Feed

Files

Ubuntu Security Notice 636-1
Posted Aug 20, 2008
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 636-1 - Sebastian Krahmer discovered that Postfix was not correctly handling mailbox ownership when dealing with Linux's implementation of hardlinking to symlinks. In certain mail spool configurations, a local attacker could exploit this to append data to arbitrary files as the root user. The default Ubuntu configuration was not vulnerable.

tags | advisory, arbitrary, local, root
systems | linux, ubuntu
advisories | CVE-2008-2936
MD5 | cce112ac7583d275595f69c51a839d9d
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close