Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Postfix不安全临时文件创建漏洞
Vulnerability Description
Debian GNU/Linux和Ubuntu postfix 2.5.5程序包的postfix.postinst脚本授予postfix用户对/var/spool/postfix/pid的写入访问权,这会允许本地用户通过执行symlink攻击来重写任意文件。
CVSS Information
N/A
Vulnerability Type
N/A