REDHAT-BUG-2466488: High severity Postfix Postfix vulnerability
Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Postfixto a version that resolves this vulnerability.Fixed in 3.8.16 - Upgrade
Upgrade
Postfixto a version that resolves this vulnerability.Fixed in 3.9.10 - Upgrade
Upgrade
Postfixto a version that resolves this vulnerability.Fixed in 3.10.9
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2466488?
The severity of REDHAT-BUG-2466488 is rated as high with a score of 7.
What are the affected versions of Postfix in REDHAT-BUG-2466488?
Postfix versions before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 are affected by REDHAT-BUG-2466488.
How do I fix REDHAT-BUG-2466488?
To fix REDHAT-BUG-2466488, upgrade to the latest versions of Postfix that are not affected by this vulnerability.
What type of vulnerability is described in REDHAT-BUG-2466488?
REDHAT-BUG-2466488 describes a buffer over-read vulnerability that can lead to a process crash.
What impact does REDHAT-BUG-2466488 have on Postfix?
The impact of REDHAT-BUG-2466488 can result in process crashes when an enhanced status code is misformatted.