CVE-2017-5930: Low severity openSUSE Leap vulnerability
The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PostfixAdmin/AliasHandlerto a version that resolves this vulnerability.Fixed in 3.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5930?
CVE-2017-5930 has a medium severity rating due to the risk of unauthorized deletion of protected aliases by authenticated users.
How do I fix CVE-2017-5930?
To fix CVE-2017-5930, upgrade PostfixAdmin to version 3.0.2 or later, which includes a proper permission check.
Who is affected by CVE-2017-5930?
Users of PostfixAdmin versions prior to 3.0.2 and certain versions of openSUSE are affected by CVE-2017-5930.
What does CVE-2017-5930 exploit?
CVE-2017-5930 exploits a missing permission check in the AliasHandler component of PostfixAdmin.
Can CVE-2017-5930 be exploited remotely?
Yes, CVE-2017-5930 can be exploited remotely by authenticated domain administrators.