Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-04-16T16:00:00

Updated: 2024-08-05T17:33:16.056Z

Reserved: 2017-06-21T00:00:00

Link: CVE-2017-10140

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-04-16T17:29:00.220

Modified: 2020-07-15T18:15:12.253

Link: CVE-2017-10140

cve-icon Redhat

Severity : Moderate

Publid Date: 2017-06-11T00:00:00Z

Links: CVE-2017-10140 - Bugzilla