Access Restriction Bypass
Affecting db5.3 package, versions <5.3.28-12+deb9u1
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.
References
CVSS Score
7.8
high severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredLow
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2017-10140
- Snyk ID
- SNYK-DEBIAN9-DB53-367995
- Disclosed
- 16 Apr, 2018
- Published
- 16 Apr, 2018