- Description
- Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 3.0
- Type
- Primary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 4.6
- Impact score
- 6.4
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:P/I:P/A:P
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C4E46DED-C952-4EC2-8418-B94092708565",
"versionEndExcluding": "2.11.10"
},
{
"criteria": "cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5514620D-4D5B-4090-9462-13C7F6EC6FC1",
"versionEndExcluding": "3.0.10",
"versionStartIncluding": "3.0.0"
},
{
"criteria": "cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FBE1FAC6-6422-43D8-8981-08359639366B",
"versionEndExcluding": "3.1.6",
"versionStartIncluding": "3.1.0"
},
{
"criteria": "cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0B5C3C4E-E289-4F5E-A211-A9EE33EDE36E",
"versionEndExcluding": "3.2.2",
"versionStartIncluding": "3.2.0"
}
],
"operator": "OR"
}
]
}
]