Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j6hx-4cv9-wrj8

Опубликовано: 21 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or digital signature checking which could allow an attacker to replace certain configuration files (e.g., phishing whitelist) via dns/packet spoofing.

The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or digital signature checking which could allow an attacker to replace certain configuration files (e.g., phishing whitelist) via dns/packet spoofing.

EPSS

Процентиль: 8%
0.00029
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 6 лет назад

The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or digital signature checking which could allow an attacker to replace certain configuration files (e.g., phishing whitelist) via dns/packet spoofing.

CVSS3: 5.5
nvd
около 6 лет назад

The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or digital signature checking which could allow an attacker to replace certain configuration files (e.g., phishing whitelist) via dns/packet spoofing.

CVSS3: 5.5
debian
около 6 лет назад

The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 down ...

EPSS

Процентиль: 8%
0.00029
Низкий