CVE-2017-10140: Postfix
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.
Affected products
- Postfix Postfix: before 2.11.10 (fixed in 2.11.10); from 3.0.0, before 3.0.10 (fixed in 3.0.10); from 3.1.0, before 3.1.6 (fixed in 3.1.6); from 3.2.0, before 3.2.2 (fixed in 3.2.2)
Published 2018-04-16. Last modified 2026-06-17.