Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1135-1 | db security update |
Debian DLA |
DLA-1136-1 | db4.8 security update |
Debian DLA |
DLA-1137-1 | db4.7 security update |
EUVD |
EUVD-2017-1787 | Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory. |
Ubuntu USN |
USN-3489-1 | Berkeley DB vulnerability |
Ubuntu USN |
USN-3489-2 | Berkeley DB vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T17:33:16.056Z
Reserved: 2017-06-21T00:00:00
Link: CVE-2017-10140
No data.
Status : Modified
Published: 2018-04-16T17:29:00.220
Modified: 2024-11-21T03:05:27.960
Link: CVE-2017-10140
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN