Secunia Security Advisory - SUSE has issued an update for postfix. This fixes some security issues, which can be exploited by malicious, local users to disclose potentially sensitive information and perform certain actions with escalated privileges.
a2b9a76730e08c1edaa1498cd8625b5d292ec32b8160f8dec8804073b7514483
----------------------------------------------------------------------
Want a new job?
http://secunia.com/secunia_security_specialist/
http://secunia.com/hardcore_disassembler_and_reverse_engineer/
International Partner Manager - Project Sales in the IT-Security
Industry:
http://corporate.secunia.com/about_secunia/64/
----------------------------------------------------------------------
TITLE:
SUSE update for postfix
SECUNIA ADVISORY ID:
SA31500
VERIFY ADVISORY:
http://secunia.com/advisories/31500/
CRITICAL:
Less critical
IMPACT:
Exposure of sensitive information, Privilege escalation
WHERE:
Local system
OPERATING SYSTEM:
openSUSE 11.0
http://secunia.com/product/19180/
openSUSE 10.3
http://secunia.com/product/16124/
openSUSE 10.2
http://secunia.com/product/13375/
SuSE Linux Enterprise Server 8
http://secunia.com/product/1171/
SUSE Linux Enterprise Server 9
http://secunia.com/product/4118/
SUSE Linux Enterprise Server 10
http://secunia.com/product/12192/
SOFTWARE:
Novell Open Enterprise Server 1.x
http://secunia.com/product/4664/
DESCRIPTION:
SUSE has issued an update for postfix. This fixes some security
issues, which can be exploited by malicious, local users to disclose
potentially sensitive information and perform certain actions with
escalated privileges.
For more information:
SA31485
SOLUTION:
Apply updated packages.
x86 Platform:
openSUSE 11.0:
http://download.opensuse.org/pub/opensuse/update-debug/11.0/rpm/i586/postfix-debuginfo-2.5.1-28.3.i586.rpm
http://download.opensuse.org/pub/opensuse/update-debug/11.0/rpm/i586/postfix-debugsource-2.5.1-28.3.i586.rpm
http://download.opensuse.org/pub/opensuse/update/11.0/rpm/i586/postfix-2.5.1-28.3.i586.rpm
http://download.opensuse.org/pub/opensuse/update/11.0/rpm/i586/postfix-devel-2.5.1-28.3.i586.rpm
http://download.opensuse.org/pub/opensuse/update/11.0/rpm/i586/postfix-mysql-2.5.1-28.3.i586.rpm
http://download.opensuse.org/pub/opensuse/update/11.0/rpm/i586/postfix-postgresql-2.5.1-28.3.i586.rpm
openSUSE 10.3:
http://download.opensuse.org/pub/opensuse/update/10.3/rpm/i586/postfix-2.4.5-20.4.i586.rpm
http://download.opensuse.org/pub/opensuse/update/10.3/rpm/i586/postfix-devel-2.4.5-20.4.i586.rpm
http://download.opensuse.org/pub/opensuse/update/10.3/rpm/i586/postfix-mysql-2.4.5-20.4.i586.rpm
http://download.opensuse.org/pub/opensuse/update/10.3/rpm/i586/postfix-postgresql-2.4.5-20.4.i586.rpm
openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/postfix-2.3.2-32.i586.rpm
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/postfix-devel-2.3.2-32.i586.rpm
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/postfix-mysql-2.3.2-32.i586.rpm
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/postfix-postgresql-2.3.2-32.i586.rpm
Sources:
openSUSE 11.0:
http://download.opensuse.org/pub/opensuse/update/11.0/rpm/src/postfix-2.5.1-28.3.src.rpm
openSUSE 10.3:
http://download.opensuse.org/pub/opensuse/update/10.3/rpm/src/postfix-2.4.5-20.4.src.rpm
openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/src/postfix-2.3.2-32.src.rpm
Open Enterprise Server
http://download.novell.com/index.jsp?search=Search&keywords=f572eea698b3b6a0124f7004ea6579c8
Novell Linux POS 9
http://download.novell.com/index.jsp?search=Search&keywords=f572eea698b3b6a0124f7004ea6579c8
Novell Linux Desktop 9
http://download.novell.com/index.jsp?search=Search&keywords=f572eea698b3b6a0124f7004ea6579c8
SuSE Linux Enterprise Server 8
http://download.novell.com/index.jsp?search=Search&keywords=f572eea698b3b6a0124f7004ea6579c8
SUSE Linux Enterprise Server 10 SP1
http://download.novell.com/index.jsp?search=Search&keywords=f572eea698b3b6a0124f7004ea6579c8
SUSE Linux Enterprise Server 10 SP2
http://download.novell.com/index.jsp?search=Search&keywords=f572eea698b3b6a0124f7004ea6579c8
SUSE Linux Enterprise Desktop 10 SP1
http://download.novell.com/index.jsp?search=Search&keywords=f572eea698b3b6a0124f7004ea6579c8
SUSE Linux Enterprise Desktop 10 SP2
http://download.novell.com/index.jsp?search=Search&keywords=f572eea698b3b6a0124f7004ea6579c8
SUSE SLES 9
http://download.novell.com/index.jsp?search=Search&keywords=f572eea698b3b6a0124f7004ea6579c8
ORIGINAL ADVISORY:
http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00002.html
OTHER REFERENCES:
SA31485:
http://secunia.com/advisories/31485/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------