Bug 456314 (CVE-2008-2936) - CVE-2008-2936 postfix privilege escalation flaw
Summary: CVE-2008-2936 postfix privilege escalation flaw
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2008-2936
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
: 459091 (view as bug list)
Depends On: 456714 456715 456716 456717 456718 459099 459100 459101 833970
Blocks:
TreeView+ depends on / blocked
 
Reported: 2008-07-22 19:16 UTC by Josh Bressers
Modified: 2023-05-11 13:09 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2008-10-10 07:27:12 UTC
Embargoed:


Attachments (Terms of Use)
Proposed upstream patch (2.31 KB, patch)
2008-07-25 18:33 UTC, Josh Bressers
no flags Details | Diff
Updated upstream patch (2.18 KB, application/octet-stream)
2008-08-07 23:54 UTC, Josh Bressers
no flags Details


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2008:0839 0 normal SHIPPED_LIVE Moderate: postfix security update 2008-08-14 19:34:55 UTC

Description Josh Bressers 2008-07-22 19:16:31 UTC
Sebastian Krahmer reported a flaw in the way postfix handle symlink files owned
by root.  If a user has write permission to the mail spool directory (this means
that the user is in the mail group on our systems, which is unlikely), and there
is no root mailbox, they can create a hard link to a root owned symlink. 
Postfix will append mail messages to an arbitrary file, which could result in
the local user gaining root privileges.

Acknowledgements:

Red Hat would like to thank Sebastian Krahmer for responsibly disclosing
this issue.

Comment 2 Josh Bressers 2008-07-22 19:19:05 UTC
This flaw affects Red Hat Enterprise Linux 3, 4, and 5.

Comment 3 Josh Bressers 2008-07-25 18:33:33 UTC
Created attachment 312664 [details]
Proposed upstream patch

Comment 5 Josh Bressers 2008-08-07 23:54:42 UTC
Created attachment 313762 [details]
Updated upstream patch

Comment 6 Josh Bressers 2008-08-08 00:01:09 UTC
Thomas,

Can you roll up some new packages for this?  I'll write up the errata tomorrow.

Thanks.

Comment 7 Josh Bressers 2008-08-08 15:14:49 UTC
This is going to be RHSA-2008-0839.

It now needs packages.

Comment 8 Josh Bressers 2008-08-14 13:20:49 UTC
This is now public:
http://archives.neohapsis.com/archives/postfix/2008-08/0392.html

Comment 9 Josh Bressers 2008-08-14 13:23:17 UTC
*** Bug 459091 has been marked as a duplicate of this bug. ***

Comment 12 Tomas Hoger 2008-09-02 07:47:29 UTC
Public PoC posted to multiple security lists:

http://marc.info/?l=bugtraq&m=122029567530728&w=4

Comment 13 Fedora Update System 2008-10-09 21:31:11 UTC
postfix-2.5.5-1.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 14 Fedora Update System 2008-10-09 21:33:09 UTC
postfix-2.5.5-1.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.