Gentoo: Postfix Local privilege escalation


 
Thread Tools Search this Thread
Special Forums Cybersecurity Security Advisories (RSS) Gentoo: Postfix Local privilege escalation
# 1  
Old 08-15-2008
Gentoo: Postfix Local privilege escalation

LinuxSecurity.com: Sebastian Krahmer of SuSE has found that Postfix allows to deliver mail to root-owned symlinks in an insecure manner under certain conditions. Normally, Postfix does not deliver mail to symlinks, except to root-owned symlinks, for compatibility with the systems using symlinks in /dev like Solaris. Furthermore, some systems like Linux allow to hardlink a symlink, while the POSIX.1-2001 standard requires that the symlink is followed.

More...
Login or Register to Ask a Question

Previous Thread | Next Thread
Login or Register to Ask a Question