Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-2936

25
FAUCET Score

CVE-2008-2936 describes a local privilege escalation vulnerability affecting Postfix versions before 2.3.15, 2.4.8, 2.5.4, and 2.6-20080814, specifically when the operating system supports hard links to symlinks. A local attacker can append email messages to a root-owned symlink by creating a hard link to it, potentially leading to privilege escalation if the symlink points to an init script. This vulnerability has a CVSS score of 6.2, indicating high impact on confidentiality, integrity, and availability, but requires high attack complexity and local access. While not listed on the KEV catalog or having significant community discussion or media coverage, an exploit for this vulnerability is publicly available on ExploitDB.

Impacted Technologies

VendorProductVersion(s)CPE
2.3.0CPE matchmatch criteria
cpe:2.3:a:postfix:postfix:2.3.0:*:*:*:*:*:*:*
2.3.1CPE matchmatch criteria
cpe:2.3:a:postfix:postfix:2.3.1:*:*:*:*:*:*:*
2.3.2CPE matchmatch criteria
cpe:2.3:a:postfix:postfix:2.3.2:*:*:*:*:*:*:*
2.3.3CPE matchmatch criteria
cpe:2.3:a:postfix:postfix:2.3.3:*:*:*:*:*:*:*
2.3.4CPE matchmatch criteria
cpe:2.3:a:postfix:postfix:2.3.4:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.2MEDIUM

AV:L/AC:H/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
HIGH
Authentication
NONE
Exploitability Score
1.9
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
1.00%
Probability of exploitation in next 30 days
EPSS Percentile
59.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
ExploitDB: EDB-6337 · Aug 31, 2008
This CVE's current EPSS score of 0.0100 is in the 90th percentile among its peer group of 1,595 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: postfix-2:2.0.16-14.1.RHEL3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: postfix-2:2.2.10-1.2.1.el4_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: postfix-2:2.3.3-2.1.el5_2
View patch

Vendor Advisories (1)

redhatCVE-2008-2936Moderate

postfix privilege escalation flaw

Aug 14, 2008

References

ftp.porcupine.org / mirrors/postfix-release/experimental/postfix-2.6-20080814.HISTORY
ftp.porcupine.org / mirrors/postfix-release/official/postfix-2.3.15.HISTORY
ftp.porcupine.org / mirrors/postfix-release/official/postfix-2.4.8.HISTORY
ftp.porcupine.org / mirrors/postfix-release/official/postfix-2.5.4.HISTORY
article.gmane.org / gmane.mail.postfix.announce/110
lists.opensuse.org / opensuse-security-announce/2008-08/msg00002.html
secunia.com / advisories/31469
secunia.com / advisories/31474
secunia.com / advisories/31477
secunia.com / advisories/31485
Vendor Advisory
secunia.com / advisories/31500
Vendor Advisory
secunia.com / advisories/31530
secunia.com / advisories/32231
security.gentoo.org / glsa/glsa-200808-12.xml
securityreason.com / securityalert/4160
exchange.xforce.ibmcloud.com / vulnerabilities/44460
issues.rpath.com / browse/RPL-2689
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10033
usn.ubuntu.com / 636-1
exploit-db.com / exploits/6337
redhat.com / archives/fedora-package-announce/2008-October/msg00271.html
redhat.com / archives/fedora-package-announce/2008-October/msg00287.html
wiki.rpath.com / Advisories:rPSA-2008-0259
debian.org / security/2008/dsa-1629
kb.cert.org / vuls/id/938323
US Government Resource
mandriva.com / security/advisories
redhat.com / support/errata/RHSA-2008-0839.html
securityfocus.com / archive/1/495474/100/0/threaded
securityfocus.com / archive/1/495632/100/0/threaded
securityfocus.com / archive/1/495882/100/0/threaded
securityfocus.com / bid/30691
Patch
securitytracker.com / id
vupen.com / english/advisories/2008/2385