QID 355069

Date Published: 2023-05-18

QID 355069: Amazon Linux Security Advisory for db4 : AL2012-2023-393

Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2017-10140:
Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory. 1464032: CVE-2017-10140 libdb: Reads DB_CONFIG from the current working directory

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Administrators are advised to apply the appropriate software updates.
    Vendor References

    CVEs related to QID 355069

    Software Advisories
    Advisory ID Software Component Link
    AL2012-2023-393 Amazon Linux Bare Metal URL Logo docs.aws.amazon.com/AWSEC2/latest/UserGuide/install-updates.html