Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-10140

Опубликовано: 16 апр. 2018
Источник: nvd
CVSS3: 7.8
CVSS2: 4.6
EPSS Низкий

Описание

Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:*
Версия до 2.11.10 (исключая)
cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.0.10 (исключая)
cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:*
Версия от 3.1.0 (включая) до 3.1.6 (исключая)
cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:*
Версия от 3.2.0 (включая) до 3.2.2 (исключая)

EPSS

Процентиль: 51%
0.00282
Низкий

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 7 лет назад

Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.

CVSS3: 4.5
redhat
около 8 лет назад

Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.

CVSS3: 7.8
debian
около 7 лет назад

Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3 ...

CVSS3: 7.8
github
около 3 лет назад

Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.

EPSS

Процентиль: 51%
0.00282
Низкий

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

NVD-CWE-noinfo