HomePostfixCVE-2008-4977

CVE-2008-4977

UNKNOWN
6.9CVSS
Published: 2008-11-06
Updated: 2025-04-09
AI Analysis

Description

postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdout, (2) /tmp/postfix_groups.stderr, and (3) /tmp/postfix_groups.message temporary files. NOTE: the vendor disputes this vulnerability, stating "This is not a real issue ... users would have to edit a script under /usr/lib to enable it.

CVSS Metrics

Vector
AV:L/AC:M/Au:N/C:C/I:C/A:C
Access Vector
local
Access Cmplx
medium
Auth
none
Confidentiality
complete
Integrity
complete
Availability
complete
Weaknesses
CWE-59

Metadata

Primary Vendor
POSTFIX
Published
11/6/2008
Last Modified
4/9/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

postfix : postfix

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief