CVE-2017-10140
published 2018-04-16CVE-2017-10140: Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented…
PriorityP337high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.57%
43.2th percentile
Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_high_sierra | — | — |
| apple | macos_high_sierra_10.13.1_security_update_2017-001_sierra_and_security_update_20 | — | — |
| debian | db5.3 | < db5.3 5.3.28-13.1 (bookworm) | db5.3 5.3.28-13.1 (bookworm) |
| postfix | postfix | < 2.11.10 | 2.11.10 |
| postfix | postfix | >= 3.0.0 < 3.0.10 | 3.0.10 |
| postfix | postfix | >= 3.1.0 < 3.1.6 | 3.1.6 |
| postfix | postfix | >= 3.2.0 < 3.2.2 | 3.2.2 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_oracle7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Berkeley DB Risk Matrix: Data Store — CVE-2017-10140
vendor_oracle·2020-07-15·CVSS 7.3
CVE-2017-10140 [HIGH] Oracle Oracle Berkeley DB Risk Matrix: Data Store — CVE-2017-10140
Oracle Oracle Berkeley DB Risk Matrix: Data Store vulnerability
CVE: CVE-2017-10140
CVSS: 7.3
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2020 (JUL 2020)
Ubuntu
Berkeley DB vulnerability
vendor_ubuntu·2017-11-21
CVE-2017-10140 Berkeley DB vulnerability
Title: Berkeley DB vulnerability
Summary: Berkeley DB could be made to expose sensitive information.
USN-3489-1 fixed a vulnerability in Berkeley DB. This update provides the
corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that Berkeley DB incorrectly handled certain configuration files.
An attacker could possibly use this issue to read sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Berkeley DB vulnerability
vendor_ubuntu·2017-11-21
CVE-2017-10140 Berkeley DB vulnerability
Title: Berkeley DB vulnerability
Summary: Berkeley DB could be made to expose sensitive information.
It was discovered that Berkeley DB incorrectly handled certain configuration files.
An attacker could possibly use this issue to read sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Apple
CVE-2017-10140: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
vendor_apple·2017-10-31·CVSS 7.8
CVE-2017-10140 [HIGH] CVE-2017-10140: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
Apple Security Update: About the security content of macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
Product: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
CVE: CVE-2017-10140
Component: Postfix
Impact: Multiple issues in Postfix
Description: Multiple issues were addressed by updating to version 3.2.2.
Apple
CVE-2017-10140: macOS High Sierra 10.13
vendor_apple·2017-09-25·CVSS 7.8
CVE-2017-10140 [HIGH] CVE-2017-10140: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-10140
Component: Postfix
Impact: Multiple issues in Postfix
Description: Multiple issues were addressed by updating to version 3.2.2.
Red Hat
libdb: Reads DB_CONFIG from the current working directory
vendor_redhat·2017-06-11·CVSS 7.8
CVE-2017-10140 [HIGH] libdb: Reads DB_CONFIG from the current working directory
libdb: Reads DB_CONFIG from the current working directory
Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.
Statement: This issue affects the versions of libdb as shipped with Red Hat Satellite 6.0, 6.1 and 6.2. This package no longer ships with Satellite 6.3. Red Hat Product Security has rated this issue as having security impact of Moderate. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Mitigation: Do not use an application using libdb if an un
Debian
CVE-2017-10140: db5.3 - Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x befor...
vendor_debian·2017·CVSS 7.8
CVE-2017-10140 [HIGH] CVE-2017-10140: db5.3 - Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x befor...
Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.
Scope: local
bookworm: resolved (fixed in 5.3.28-13.1)
bullseye: resolved (fixed in 5.3.28-13.1)
forky: resolved (fixed in 5.3.28-13.1)
sid: resolved (fixed in 5.3.28-13.1)
trixie: resolved (fixed in 5.3.28-13.1)
GHSA
GHSA-698c-frxg-8qf9: Postfix before 2
ghsa_unreviewed·2022-05-13
CVE-2017-10140 [HIGH] GHSA-698c-frxg-8qf9: Postfix before 2
Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.
OSV
CVE-2017-10140: Postfix before 2
osv·2018-04-16·CVSS 7.8
CVE-2017-10140 [HIGH] CVE-2017-10140: Postfix before 2
Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-10140 libdb4: libdb: Reads DB_CONFIG from the current working directory [fedora-all]
bugzilla·2017-06-22·CVSS 7.8
CVE-2017-10140 [HIGH] CVE-2017-10140 libdb4: libdb: Reads DB_CONFIG from the current working directory [fedora-all]
CVE-2017-10140 libdb4: libdb: Reads DB_CONFIG from the current working directory [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2017-10140 libdb: Reads DB_CONFIG from the current working directory [fedora-all]
bugzilla·2017-06-22·CVSS 7.8
CVE-2017-10140 [HIGH] CVE-2017-10140 libdb: Reads DB_CONFIG from the current working directory [fedora-all]
CVE-2017-10140 libdb: Reads DB_CONFIG from the current working directory [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2017-10140 postfix: libdb: Reads DB_CONFIG from the current working directory [fedora-all]
bugzilla·2017-06-22·CVSS 7.8
CVE-2017-10140 [HIGH] CVE-2017-10140 postfix: libdb: Reads DB_CONFIG from the current working directory [fedora-all]
CVE-2017-10140 postfix: libdb: Reads DB_CONFIG from the current working directory [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple s
Bugzilla
CVE-2017-10140 libdb: Reads DB_CONFIG from the current working directory
bugzilla·2017-06-22·CVSS 7.8
CVE-2017-10140 [HIGH] CVE-2017-10140 libdb: Reads DB_CONFIG from the current working directory
CVE-2017-10140 libdb: Reads DB_CONFIG from the current working directory
It was found that Berkeley DB reads the DB_CONFIG configuration file from the current working directory by default. This happens when calling db_create() with dbenv=NULL; or using the dbm_open() function.
References:
http://seclists.org/oss-sec/2017/q2/452
http://www.postfix.org/announcements/postfix-3.2.2.html
Proposed patch:
http://seclists.org/oss-sec/2017/q2/475
Discussion:
Created libdb tracking bugs for this issue:
Affects: fedora-all [bug 1464033]
Created libdb4 tracking bugs for this issue:
Affects: fedora-all [bug 1464035]
Created postfix tracking bugs for this issue:
Affects: fedora-all [bug 1464034]
---
Easy to reproduce with a simple application that creates and opens a database without exp
http://seclists.org/oss-sec/2017/q3/285http://www.postfix.org/announcements/postfix-3.2.2.htmlhttps://access.redhat.com/errata/RHSA-2019:0366https://www.oracle.com/security-alerts/cpujul2020.htmlhttp://seclists.org/oss-sec/2017/q3/285http://www.postfix.org/announcements/postfix-3.2.2.htmlhttps://access.redhat.com/errata/RHSA-2019:0366https://www.oracle.com/security-alerts/cpujul2020.html
2018-04-16
Published