CVE-2009-2939: Medium severity postfix vulnerability
The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2939?
CVE-2009-2939 has a medium severity rating due to the potential for local users to conduct symlink attacks.
How do I fix CVE-2009-2939?
To fix CVE-2009-2939, upgrade to a patched version of Postfix or modify permissions to restrict write access for the postfix user.
Which systems are affected by CVE-2009-2939?
CVE-2009-2939 affects the Postfix package version 2.5.5 on Debian GNU/Linux and Ubuntu systems.
What are the potential exploits of CVE-2009-2939?
Exploiting CVE-2009-2939 allows local users to create symlinks that could be used to overwrite arbitrary files.
Is CVE-2009-2939 related to any specific software versions?
Yes, CVE-2009-2939 specifically affects Postfix version 2.5.5 in Debian and Ubuntu systems.