CVE-2017-10140
Last modified
CVE-2017-10140 is a vulnerability of currently unknown severity. Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Postfix | Postfix | < 2.11.10 |
| Postfix | Postfix | >= 3.0.0, < 3.0.10 |
| Postfix | Postfix | >= 3.1.0, < 3.1.6 |
| Postfix | Postfix | >= 3.2.0, < 3.2.2 |
References
- http://seclists.org/oss-sec/2017/q3/285Exploit, Mailing List, Third Party Advisory
- http://www.postfix.org/announcements/postfix-3.2.2.htmlVendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0366Third Party Advisory
- http://seclists.org/oss-sec/2017/q3/285Exploit, Mailing List, Third Party Advisory
- http://www.postfix.org/announcements/postfix-3.2.2.htmlVendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0366Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-10140?
How severe is CVE-2017-10140?
How do I fix CVE-2017-10140?
Are you affected by CVE-2017-10140?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
