Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.881278
Category:CentOS Local Security Checks
Title:CentOS Update for postfix CESA-2011:0422 centos4 x86_64
Summary:The remote host is missing an update for the 'postfix'; package(s) announced via the referenced advisory.
Description:Summary:
The remote host is missing an update for the 'postfix'
package(s) announced via the referenced advisory.

Vulnerability Insight:
Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL),
and TLS.

It was discovered that Postfix did not flush the received SMTP commands
buffer after switching to TLS encryption for an SMTP session. A
man-in-the-middle attacker could use this flaw to inject SMTP commands into
a victim's session during the plain text phase. This would lead to those
commands being processed by Postfix after TLS encryption is enabled,
possibly allowing the attacker to steal the victim's mail or authentication
credentials. (CVE-2011-0411)

It was discovered that Postfix did not properly check the permissions of
users' mailbox files. A local attacker able to create files in the mail
spool directory could use this flaw to create mailbox files for other local
users, and be able to read mail delivered to those users. (CVE-2008-2937)

Red Hat would like to thank the CERT/CC for reporting CVE-2011-0411, and
Sebastian Krahmer of the SuSE Security Team for reporting CVE-2008-2937.
The CERT/CC acknowledges Wietse Venema as the original reporter of
CVE-2011-0411.

Users of Postfix are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing this
update, the postfix service will be restarted automatically.

Affected Software/OS:
postfix on CentOS 4

Solution:
Please install the updated packages.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-2937
20080821 rPSA-2008-0259-1 postfix
http://www.securityfocus.com/archive/1/495632/100/0/threaded
30691
http://www.securityfocus.com/bid/30691
31477
http://secunia.com/advisories/31477
31485
http://secunia.com/advisories/31485
31500
http://secunia.com/advisories/31500
32231
http://secunia.com/advisories/32231
ADV-2008-2385
http://www.vupen.com/english/advisories/2008/2385
FEDORA-2008-8593
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00287.html
FEDORA-2008-8595
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00271.html
GLSA-200808-12
http://security.gentoo.org/glsa/glsa-200808-12.xml
MDVSA-2009:224
http://www.mandriva.com/security/advisories?name=MDVSA-2009:224
RHSA-2011:0422
http://www.redhat.com/support/errata/RHSA-2011-0422.html
SUSE-SA:2008:040
http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00002.html
ftp://ftp.porcupine.org/mirrors/postfix-release/experimental/postfix-2.6-20080814.HISTORY
ftp://ftp.porcupine.org/mirrors/postfix-release/official/postfix-2.5.4.HISTORY
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://wiki.rpath.com/Advisories:rPSA-2008-0259
https://issues.rpath.com/browse/RPL-2689
postfix-email-information-disclosure(44461)
https://exchange.xforce.ibmcloud.com/vulnerabilities/44461
Common Vulnerability Exposure (CVE) ID: CVE-2011-0411
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html
BugTraq ID: 46767
http://www.securityfocus.com/bid/46767
CERT/CC vulnerability note: VU#555316
http://www.kb.cert.org/vuls/id/555316
Debian Security Information: DSA-2233 (Google Search)
http://www.debian.org/security/2011/dsa-2233
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056560.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056559.html
http://security.gentoo.org/glsa/glsa-201206-33.xml
http://www.openwall.com/lists/oss-security/2021/08/10/2
http://www.osvdb.org/71021
http://www.redhat.com/support/errata/RHSA-2011-0423.html
http://securitytracker.com/id?1025179
http://secunia.com/advisories/43646
http://secunia.com/advisories/43874
SuSE Security Announcement: SUSE-SR:2011:009 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html
http://www.vupen.com/english/advisories/2011/0611
http://www.vupen.com/english/advisories/2011/0752
http://www.vupen.com/english/advisories/2011/0891
XForce ISS Database: multiple-starttls-command-execution(65932)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65932
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.