CVE-2008-4977: Medium severity plone vulnerability
DISPUTED postfixgroups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfixgroups.stdout, (2) /tmp/postfixgroups.stderr, and (3) /tmp/postfixgroups.message temporary files. NOTE: the vendor disputes this vulnerability, stating "This is not a real issue ... users would have to edit a script under /usr/lib to enable it."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4977?
CVE-2008-4977 is disputed by the vendor, so its severity level is unclear but it involves local file overwrite risks.
How do I fix CVE-2008-4977?
To mitigate CVE-2008-4977, ensure that Postfix is updated to a version higher than 2.5.2 and check for symlink protections.
Who is affected by CVE-2008-4977?
CVE-2008-4977 affects users of Postfix version 2.5.2 on systems where local users can create symlinks.
What method does CVE-2008-4977 utilize for exploitation?
CVE-2008-4977 exploits a symlink attack via temporary files created by postfix_groups.pl.
Is it safe to use Postfix version 2.5.2 given CVE-2008-4977?
Using Postfix version 2.5.2 is not recommended due to potential risks associated with CVE-2008-4977.