cbcvebase.
CVE-2017-10140
published 2018-04-16

CVE-2017-10140: Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented…

PriorityP337high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.57%
43.2th percentile
Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.

Affected

7 ranges
VendorProductVersion rangeFixed in
applemacos_high_sierra
applemacos_high_sierra_10.13.1_security_update_2017-001_sierra_and_security_update_20
debiandb5.3< db5.3 5.3.28-13.1 (bookworm)db5.3 5.3.28-13.1 (bookworm)
postfixpostfix< 2.11.102.11.10
postfixpostfix>= 3.0.0 < 3.0.103.0.10
postfixpostfix>= 3.1.0 < 3.1.63.1.6
postfixpostfix>= 3.2.0 < 3.2.23.2.2

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_oracle7.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.