First published: Thu Jun 22 2017(Updated: )
It was found that Berkeley DB reads the DB_CONFIG configuration file from the current working directory by default. This happens when calling db_create() with dbenv=NULL; or using the dbm_open() function. References: <a href="http://seclists.org/oss-sec/2017/q2/452">http://seclists.org/oss-sec/2017/q2/452</a> <a href="http://www.postfix.org/announcements/postfix-3.2.2.html">http://www.postfix.org/announcements/postfix-3.2.2.html</a> Proposed patch: <a href="http://seclists.org/oss-sec/2017/q2/475">http://seclists.org/oss-sec/2017/q2/475</a>
Credit: an anonymous researcher an anonymous researcher cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS High Sierra | <10.13.1 | 10.13.1 |
Apple Sierra | ||
Apple El Capitan | ||
Postfix Postfix | <2.11.10 | |
Postfix Postfix | >=3.0.0<3.0.10 | |
Postfix Postfix | >=3.1.0<3.1.6 | |
Postfix Postfix | >=3.2.0<3.2.2 | |
Apple macOS High Sierra | <10.13 | 10.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-10140 is a vulnerability in Postfix that allows local users to gain privileges.
CVE-2017-10140 affects Postfix versions before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2.
The severity level of CVE-2017-10140 is high with a score of 7.8.
You can fix CVE-2017-10140 by updating Postfix to version 3.2.2.
You can find more information about CVE-2017-10140 at the following references: [http://seclists.org/oss-sec/2017/q2/452](http://seclists.org/oss-sec/2017/q2/452), [http://www.postfix.org/announcements/postfix-3.2.2.html](http://www.postfix.org/announcements/postfix-3.2.2.html), [http://seclists.org/oss-sec/2017/q2/475](http://seclists.org/oss-sec/2017/q2/475)