Title : Debian Security Update Fixes Postfix Privilege Escalation Vulnerability VUPEN ID : VUPEN/ADV-2008-2402 CVE ID : CVE-2008-2936
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-08-19
Technical Description
A vulnerability has been identified in Debian, which could be exploited by malicious users to bypass security restrictions and potentially obtain elevated privileges. This issue is caused by an error in Postfix. For additional information, see : VUPEN/ADV-2008-2385
Debian GNU/Linux etch - Upgrade to postfix version 2.3.8-2+etch1
Debian GNU/Linux sid - Upgrade to postfix version 2.5.4-1
Debian GNU/Linux lenny - Upgrade to postfix version 2.5.2-2lenny1 References