PT-2023-6518 · Opensuse+1 · Opensuse Leap+3
Matthias Gerstner
·
Publicado
2023-08-23
·
Atualizado
2024-06-15
·
CVE-2023-32182
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
postfix versions prior to 3.7.3-150500.3.5.1 in SUSE Linux Enterprise Desktop 15 SP5
postfix versions prior to 3.7.3-150500.3.5.1 in SUSE Linux Enterprise High Performance Computing 15 SP5
postfix versions prior to 3.7.3-150500.3.5.1 in openSUSE Leap 15.5
Description
The issue is related to an Improper Link Resolution Before File Access ('Link Following') vulnerability in the postfix package of certain SUSE and openSUSE operating systems. This vulnerability may allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations
For SUSE Linux Enterprise Desktop 15 SP5, update postfix to version 3.7.3-150500.3.5.1 or later.
For SUSE Linux Enterprise High Performance Computing 15 SP5, update postfix to version 3.7.3-150500.3.5.1 or later.
For openSUSE Leap 15.5, update postfix to version 3.7.3-150500.3.5.1 or later.
Exploit
Correção
Link Following
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Suse Linux Enterprise Desktop
Suse Linux Enterprise High Performance Computing
Suse
Opensuse Leap