HomePostfixCVE-2008-2937

CVE-2008-2937

UNKNOWN
1.9CVSS
Published: 2008-08-18
Updated: 2025-04-09
AI Analysis

Description

Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which allows local users to read e-mail messages by creating a mailbox file corresponding to another user's account name.

CVSS Metrics

Vector
AV:L/AC:M/Au:N/C:P/I:N/A:N
Access Vector
local
Access Cmplx
medium
Auth
none
Confidentiality
partial
Integrity
none
Availability
none
Weaknesses
CWE-200

Metadata

Primary Vendor
POSTFIX
Published
8/18/2008
Last Modified
4/9/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

postfix : postfixpostfix : postfixpostfix : postfixpostfix : postfixpostfix : postfix

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief