Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-10140

Опубликовано: 16 апр. 2018
Источник: debian
EPSS Низкий

Описание

Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
db5.3fixed5.3.28-13.1package
db5.3fixed5.3.28-12+deb9u1stretchpackage
db5.3fixed5.3.28-9+deb8u1jessiepackage
db5.2removedpackage
db5.1removedpackage
db4.8removedpackage
db4.7removedpackage
db4.6removedpackage
db4.5removedpackage
db4.4removedpackage
db4.3removedpackage
db4.2removedpackage
db4.1removedpackage
db4.0removedpackage
dbremovedpackage
dbfixed5.1.29-9+deb8u1jessiepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2017/08/12/1

  • Patch as used in Fedora: https://src.fedoraproject.org/rpms/libdb/raw/8047fa8580659fcae740c25e91b490539b8453eb/f/db-5.3.28-cwd-db_config.patch

  • and is acknowledged by libdb upstream, cf. https://bugzilla.redhat.com/show_bug.cgi?id=1464032#c9

EPSS

Процентиль: 51%
0.00282
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 7 лет назад

Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.

CVSS3: 4.5
redhat
около 8 лет назад

Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.

CVSS3: 7.8
nvd
около 7 лет назад

Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.

CVSS3: 7.8
github
около 3 лет назад

Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.

EPSS

Процентиль: 51%
0.00282
Низкий