Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-10140

Опубликовано: 11 июн. 2017
Источник: redhat
CVSS3: 4.5

Описание

Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.

Отчет

This issue affects the versions of libdb as shipped with Red Hat Satellite 6.0, 6.1 and 6.2. This package no longer ships with Satellite 6.3. Red Hat Product Security has rated this issue as having security impact of Moderate. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Меры по смягчению последствий

Do not use an application using libdb if an untrusted user can create a DB_CONFIG file in its working directory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 8db4Under investigation
Red Hat Enterprise Linux 5db4Will not fix
Red Hat Enterprise Linux 5postfixWill not fix
Red Hat Enterprise Linux 6db4Will not fix
Red Hat Enterprise Linux 6postfixWill not fix
Red Hat Enterprise Linux 7libdbWill not fix
Red Hat Enterprise Linux 7postfixWill not fix
Red Hat Enterprise Linux 8libdbNot affected
Red Hat Enterprise Linux 8postfixNot affected
Red Hat JBoss Enterprise Application Platform 5httpdWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1464032libdb: Reads DB_CONFIG from the current working directory

4.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 7 лет назад

Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.

CVSS3: 7.8
nvd
около 7 лет назад

Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.

CVSS3: 7.8
debian
около 7 лет назад

Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3 ...

CVSS3: 7.8
github
около 3 лет назад

Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.

4.5 Medium

CVSS3