Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h92m-42h4-82f6

Опубликовано: 05 июл. 2019
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 6.9

Описание

postfix-mta-sts-resolver Algorithm Downgrade vulnerability

Incorrect query parsing

Impact

All users of versions prior to 0.5.1 can receive incorrect response from daemon under rare conditions, rendering downgrade of effective STS policy.

Patches

Problem has been patched in version 0.5.1

Workarounds

Users may remediate this vulnerability without upgrading by applying these patches to older suppoorted versions.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

postfix-mta-sts-resolver

pip
Затронутые версииВерсия исправления

< 0.5.1

0.5.1

EPSS

Процентиль: 53%
0.003
Низкий

8.7 High

CVSS4

6.9 Medium

CVSS3

Дефекты

CWE-757

Связанные уязвимости

CVSS3: 6.9
ubuntu
около 6 лет назад

In postfix-mta-sts-resolver before 0.5.1, All users can receive incorrect response from daemon under rare conditions, rendering downgrade of effective STS policy.

CVSS3: 6.9
nvd
около 6 лет назад

In postfix-mta-sts-resolver before 0.5.1, All users can receive incorrect response from daemon under rare conditions, rendering downgrade of effective STS policy.

CVSS3: 6.9
debian
около 6 лет назад

In postfix-mta-sts-resolver before 0.5.1, All users can receive incorr ...

EPSS

Процентиль: 53%
0.003
Низкий

8.7 High

CVSS4

6.9 Medium

CVSS3

Дефекты

CWE-757