Package: postfix
Version: 3.11.4-1
Severity: serious
https://ci.debian.net/packages/p/postfix/testing/amd64/72678864/ and confirmed
locally:
======================================================================
ERROR: test_11_security_CVE_2008_2936
(__main__.PostfixTest.test_11_security_CVE_2008_2936)
CVE-2008-2936 fixed
----------------------------------------------------------------------
Traceback (most recent call last):
File "/tmp/autopkgtest.k8hH1V/build.5uA/src/debian/tests/test-postfix.py",
line 393, in test_11_security_CVE_2008_2936
os.link('/var/tmp/secret.link','/var/mail/%s' % (self.user.login))
~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
PermissionError: [Errno 13] Permission denied: '/var/tmp/secret.link' ->
'/var/mail/tjevyrai'
-- System Information:
Debian Release: forky/sid
APT prefers unstable-debug
APT policy: (500, 'unstable-debug'), (500, 'unstable'), (500, 'testing'),
(101, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386
Kernel: Linux 7.0.13+deb14-amd64 (SMP w/16 CPU threads; PREEMPT)
Kernel taint flags: TAINT_OOT_MODULE, TAINT_UNSIGNED_MODULE
Locale: LANG=ru_RU.UTF-8, LC_CTYPE=ru_RU.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
Versions of packages postfix depends on:
ii debconf [debconf-2.0] 1.5.92
ii init-system-helpers 1.69
ii libc6 2.42-17
ii libcdb1 0.81-2+b2
ii libdb5.3t64 5.3.28+dfsg2-11+b1
ii libicu78 78.3-2
ii liblmdb0 0.9.31-1+b3
ii libnsl3 2.0.1-2
ii libsasl2-2 2.1.28+dfsg1-11
ii libssl3t64 3.6.3-1
ii libtlsrpt0 0.5.1~rc1-2
ii netbase 6.5
ii systemd [systemd-tmpfiles] 261.1-2
Versions of packages postfix recommends:
ii ca-certificates 20260601
ii python3 3.13.9-3+b1
ii ssl-cert 1.1.3
Versions of packages postfix suggests:
ii bsd-mailx [mail-reader] 8.1.2-0.20220412cvs-1.1
ii dovecot-core [dovecot-common] 1:2.4.4+dfsg1-1+b1
ii libsasl2-modules 2.1.28+dfsg1-11
ii mutt [mail-reader] 2.4.0-1
pn postfix-doc <none>
pn postfix-ldap <none>
pn postfix-mongodb <none>
pn postfix-mta-sts-resolver <none>
pn postfix-mysql <none>
pn postfix-pcre <none>
pn postfix-pgsql <none>
pn postfix-sqlite <none>
ii procmail 3.24+really3.22-5
ii s-nail [mail-reader] 14.9.25-2
ii systemd-resolved [resolvconf] 261.1-2
pn ufw <none>
-- Configuration Files:
/etc/postfix/main.cf.proto changed [not included]
-- debconf-show failed