Summary: | <mail-mta/postfix-2.4.9 / <2.5.5 epoll local DoS (CVE-2008-3889) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Tobias Scherbaum (RETIRED) <dertobi123> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | net-mail+disabled |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www.postfix.org/announcements/20080902.html | ||
Whiteboard: | A3 [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Tobias Scherbaum (RETIRED)
![]() Fixed versions are inCVS, I also removed older 2.2 and 2.3 versions. This is what should be marked as stable: =mail-mta/postfix-2.4.9 =mail-mta/postfix-2.5.5 Arches, please test and mark stable (as above): Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86" ppc and ppc64 done. amd64 stable 03 Sep 2008; Raúl Porcel <armin76@gentoo.org> postfix-2.4.9.ebuild, postfix-2.5.5.ebuild: alpha/ia64/sparc/x86 stable wrt #236453 Stable for HPPA. GLSA request filed. CVE-2008-3889 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3889): Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors during execution of "non-Postfix" commands, which allows local users to cause a denial of service (application slowdown or exit) via a crafted command, as demonstrated by a command in a .forward file. GLSA 200809-09. |