CVE.RADIO
FREN

CVE-2008-2936

postfixVulnerabilityPatched

No public exploitation has been reported so far. A fixed version is available (see the table below).

Recommended action: Update to the fixed version listed for your distribution using the native package manager.

Affected & fixed versions by distribution

Versions are the native distribution strings (backport-aware): RHEL/Debian/SUSE backport fixes, so compare with the distro version comparator (dpkg / rpm / vercmp), not the upstream version.

DistributionPackageAffectedFixed versionStatus
Debian:11postfix-2.5.4-1fixed
Debian:12postfix-2.5.4-1fixed
Debian:13postfix-2.5.4-1fixed
Debian:14postfix-2.5.4-1fixed
Debian:4.0postfix-2.3.8-2etch1fixed
Debian:4.0postfix-2.3.8-2+etch1fixed
Debian:5.0postfix-2.5.2-2lenny1fixed
Red Hat:enterprise_linux:3::aspostfix-2:2.0.16-14.1.RHEL3fixed
Red Hat:enterprise_linux:3::desktoppostfix-2:2.0.16-14.1.RHEL3fixed
Red Hat:enterprise_linux:3::espostfix-2:2.0.16-14.1.RHEL3fixed
Red Hat:enterprise_linux:3::wspostfix-2:2.0.16-14.1.RHEL3fixed
Red Hat:enterprise_linux:4::aspostfix-2:2.2.10-1.2.1.el4_7fixed
Red Hat:enterprise_linux:4::desktoppostfix-2:2.2.10-1.2.1.el4_7fixed
Red Hat:enterprise_linux:4::espostfix-2:2.2.10-1.2.1.el4_7fixed
Red Hat:enterprise_linux:4::wspostfix-2:2.2.10-1.2.1.el4_7fixed
Red Hat:enterprise_linux:5::clientpostfix-2:2.3.3-2.1.el5_2fixed
Red Hat:enterprise_linux:5::serverpostfix-2:2.3.3-2.1.el5_2fixed

Sources