CVE-2017-10140
libdb: Reads DB_CONFIG from the current working directory
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.
Postfix, en versiones anteriores a la 2.11.10, versiones 3.0.x anteriores a la 3.0.10, versiones 3.1.x anteriores a la 3.1.6 y versiones 3.2.x anteriores a la 3.2.2, podría permitir que usuarios locales obtengan privilegios aprovechando una funcionalidad no documentada en Berkeley DB, en versiones 2.x y posteriores. Esto está relacionado con la lectura de opciones de DB_CONFIG en el directorio actual.
This release adds the new Apache HTTP Server 2.4.29 Service Pack 1 packages that are part of the JBoss Core Services offering. This release serves as a replacement for Red Hat JBoss Core Services Apache HTTP Server 2.4.29, and includes bug fixes and enhancements. Issues addressed include bypass, denial of service, null pointer, out of bounds write, traversal, and use-after-free vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-06-21 CVE Reserved
- 2017-11-22 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://www.oracle.com/security-alerts/cpujul2020.html | X_refsource_misc |
|
URL | Date | SRC |
---|---|---|
http://seclists.org/oss-sec/2017/q3/285 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.postfix.org/announcements/postfix-3.2.2.html | 2020-07-15 | |
https://access.redhat.com/errata/RHSA-2019:0366 | 2020-07-15 | |
https://access.redhat.com/security/cve/CVE-2017-10140 | 2019-02-18 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1464032 | 2019-02-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Postfix Search vendor "Postfix" | Postfix Search vendor "Postfix" for product "Postfix" | < 2.11.10 Search vendor "Postfix" for product "Postfix" and version " < 2.11.10" | - |
Affected
| ||||||
Postfix Search vendor "Postfix" | Postfix Search vendor "Postfix" for product "Postfix" | >= 3.0.0 < 3.0.10 Search vendor "Postfix" for product "Postfix" and version " >= 3.0.0 < 3.0.10" | - |
Affected
| ||||||
Postfix Search vendor "Postfix" | Postfix Search vendor "Postfix" for product "Postfix" | >= 3.1.0 < 3.1.6 Search vendor "Postfix" for product "Postfix" and version " >= 3.1.0 < 3.1.6" | - |
Affected
| ||||||
Postfix Search vendor "Postfix" | Postfix Search vendor "Postfix" for product "Postfix" | >= 3.2.0 < 3.2.2 Search vendor "Postfix" for product "Postfix" and version " >= 3.2.0 < 3.2.2" | - |
Affected
|