SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#938323

Postfix local privilege escalation

Overview

The Postfix MTA contains a local privilege escalation vulnerability.

I. Description

Postfix is an mail transport agent (MTA) that is used by several Unix-like operating systems. Symbolic links and hard links are types of files that reference other files. Unlike hard links, symbolic links can point to directories and use relative pathnames.

On some non-POSIX.1-2001 and X/Open XPG4v2 compliant systems, users can hardlink symlinks which are owned by the root user. Postfix allows root-owned symlinks to be used as a mail destination folder. A hard link to a Postfix root-owned symlink could point to a file that can be overwritten by Postfix, regardless of the permissions of the destination file.

II. Impact

A local, authenticated attacker may be able to overwrite arbitrary files, possibly gaining elevated privileges.

III. Solution

Upgrade

See http://article.gmane.org/gmane.mail.postfix.announce/110 for information about obtaining updated software. Users who do not compile Postfix from source should see the systems affected section below for a partial list of affected vendors.

Set mailbox permissions

Making the system mail spool directory root-owned may mitigate this vulnerability. See http://article.gmane.org/gmane.mail.postfix.announce/110 for specific information about this and other workarounds.

Systems Affected

VendorStatusDate NotifiedDate Updated
Apple Computer, Inc.Unknown19-Aug-2008
Conectiva Inc.Unknown1-Aug-2008
Cray Inc.Unknown1-Aug-2008
Debian GNU/LinuxUnknown1-Aug-2008
DragonFly BSD ProjectNot Vulnerable2-Aug-2008
EMC CorporationUnknown1-Aug-2008
Engarde Secure LinuxUnknown1-Aug-2008
F5 Networks, Inc.Unknown1-Aug-2008
Fedora ProjectUnknown1-Aug-2008
FreeBSD, Inc.Unknown1-Aug-2008
FujitsuUnknown1-Aug-2008
Gentoo LinuxVulnerable18-Aug-2008
Hewlett-Packard CompanyUnknown1-Aug-2008
HitachiUnknown1-Aug-2008
IBM CorporationUnknown1-Aug-2008
IBM Corporation (zseries)Unknown1-Aug-2008
IBM eServerUnknown1-Aug-2008
Ingrian Networks, Inc.Unknown1-Aug-2008
Juniper Networks, Inc.Unknown1-Aug-2008
Mandriva, Inc.Vulnerable18-Aug-2008
Microsoft CorporationUnknown1-Aug-2008
MontaVista Software, Inc.Unknown1-Aug-2008
NEC CorporationUnknown1-Aug-2008
NetBSDUnknown1-Aug-2008
NokiaUnknown1-Aug-2008
Novell, Inc.Unknown1-Aug-2008
Openwall GNU/*/LinuxUnknown1-Aug-2008
QNX, Software Systems, Inc.Unknown1-Aug-2008
Red Hat, Inc.Unknown1-Aug-2008
Silicon Graphics, Inc.Unknown1-Aug-2008
Slackware Linux Inc.Unknown1-Aug-2008
Sony CorporationUnknown1-Aug-2008
Sun Microsystems, Inc.Not Vulnerable19-Aug-2008
SUSE LinuxVulnerable18-Aug-2008
The SCO GroupUnknown1-Aug-2008
TurbolinuxUnknown1-Aug-2008
UbuntuVulnerable19-Aug-2008
UnisysUnknown1-Aug-2008
Wind River Systems, Inc.Unknown1-Aug-2008

References


ftp://ftp.porcupine.org/mirrors/postfix-release/index/html
http://article.gmane.org/gmane.mail.postfix.announce/110
http://linuxgazette.net/105/pitcher.html
http://en.wikipedia.org/wiki/Hard_links
http://en.wikipedia.org/wiki/Symbolic_link

Credit

Thanks to Wietse Venema for information that was used in this report. Sebastian Krahmer of SuSE is credited for discovering and reporting this issue.

This document was written by Ryan Giobbi.

Other Information

Date Public:2008-08-18
Date First Published:2008-08-18
Date Last Updated:2008-08-19
CERT Advisory: 
CVE-ID(s):CVE-2008-2936
NVD-ID(s):CVE-2008-2936
US-CERT Technical Alerts: 
Metric:4.20
Document Revision:20

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2008 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader