Summary
This host is installed with MailScanner and is prone to multiple vulnerabilities.
Impact
Successful exploitation will let the attacker execute arbitrary codes in the context of the application and can compromise a vulnerable system.
Solution
Upgrade to the latest MailScanner version 4.74.7-2 or later http://www.mailscanner.info/downloads.html
Insight
The flaws are due to,
- Several autoupdate scripts for f-prot-autoupdate, clamav-autoupdate, panda-autoupdate, trend-autoupdate, bitdefender-wrapper, kaspersky-wrapper etc. use temporary files in an insecure manner.
- The SpamAssassin and TNEF handlers use temporary files in an insecure manner.
These can be exploited to affects local users to overwrite arbitrary files via symlink attacks.
Affected
MailScanner version prior to 4.74.7-2 on Linux.
References
Severity
Classification
-
CVE CVE-2008-5312, CVE-2008-5313 -
CVSS Base Score: 6.9
AV:L/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities