Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message. NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Postfix 权限许可和访问控制问题漏洞
Vulnerability Description
Postfix是一款开源的邮件传输代理。 Postfix 2.3.15之前版本、2.4.8之前的2.4.x版本、2.5.4之前的2.5.x版本和2.6-20080814之前的2.6x版本存在权限许可和访问控制问题漏洞,该漏洞源于当操作系统支持符号链接的硬链接时,允许本地用户通过创建一个指向该符号链接的硬链接,然后发送消息,将电子邮件附加到一个根目录下的文件。
CVSS Information
N/A
Vulnerability Type
N/A