Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.8.16CPE matchmatch criteria | cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:* | ||
>= 3.9.0, < 3.9.10CPE matchmatch criteria | cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:* | ||
>= 3.10.0, < 3.10.9CPE matchmatch criteria | cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:* | ||
>= 3.10, < 3.10.9CPE match | cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:* | ||
>= 2.3, < 3.8.16CPE match | cpe:2.3:a:postfix:postfix:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.