Bug 456314 - (CVE-2008-2936) CVE-2008-2936 postfix privilege escalation flaw
CVE-2008-2936 postfix privilege escalation flaw
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,source=vendorsec,publ...
: Security
: 459091 (view as bug list)
Depends On: 456714 456715 456716 456717 456718 459099 459100 459101 833970
Blocks:
  Show dependency treegraph
 
Reported: 2008-07-22 15:16 EDT by Josh Bressers
Modified: 2012-06-20 10:34 EDT (History)
5 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2008-10-10 03:27:12 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)
Proposed upstream patch (2.31 KB, patch)
2008-07-25 14:33 EDT, Josh Bressers
no flags Details | Diff
Updated upstream patch (2.18 KB, application/octet-stream)
2008-08-07 19:54 EDT, Josh Bressers
no flags Details

  None (edit)
Description Josh Bressers 2008-07-22 15:16:31 EDT
Sebastian Krahmer reported a flaw in the way postfix handle symlink files owned
by root.  If a user has write permission to the mail spool directory (this means
that the user is in the mail group on our systems, which is unlikely), and there
is no root mailbox, they can create a hard link to a root owned symlink. 
Postfix will append mail messages to an arbitrary file, which could result in
the local user gaining root privileges.

Acknowledgements:

Red Hat would like to thank Sebastian Krahmer for responsibly disclosing
this issue.
Comment 2 Josh Bressers 2008-07-22 15:19:05 EDT
This flaw affects Red Hat Enterprise Linux 3, 4, and 5.
Comment 3 Josh Bressers 2008-07-25 14:33:33 EDT
Created attachment 312664 [details]
Proposed upstream patch
Comment 5 Josh Bressers 2008-08-07 19:54:42 EDT
Created attachment 313762 [details]
Updated upstream patch
Comment 6 Josh Bressers 2008-08-07 20:01:09 EDT
Thomas,

Can you roll up some new packages for this?  I'll write up the errata tomorrow.

Thanks.
Comment 7 Josh Bressers 2008-08-08 11:14:49 EDT
This is going to be RHSA-2008-0839.

It now needs packages.
Comment 8 Josh Bressers 2008-08-14 09:20:49 EDT
This is now public:
http://archives.neohapsis.com/archives/postfix/2008-08/0392.html
Comment 9 Josh Bressers 2008-08-14 09:23:17 EDT
*** Bug 459091 has been marked as a duplicate of this bug. ***
Comment 12 Tomas Hoger 2008-09-02 03:47:29 EDT
Public PoC posted to multiple security lists:

http://marc.info/?l=bugtraq&m=122029567530728&w=4
Comment 13 Fedora Update System 2008-10-09 17:31:11 EDT
postfix-2.5.5-1.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 14 Fedora Update System 2008-10-09 17:33:09 EDT
postfix-2.5.5-1.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.