Incorrect default permissions in postfix - CVE-2023-32182

 

Incorrect default permissions in postfix - CVE-2023-32182

Published: August 24, 2023


Vulnerability identifier: #VU79949
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32182
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to incorrect default permissions for files in the /tmp folder set by the config_postfix script. A local user can perform a denial of service (DoS) attack.


Affected software

postfix
postfix-doc
postfix-mysql-debuginfo
postfix-mysql
postfix-debuginfo
postfix-devel
postfix-debugsource
postfix-lmdb
postfix-lmdb-debuginfo
postfix-ldap-debuginfo
postfix-bdb-lmdb
postfix-bdb-debugsource
postfix-postgresql-debuginfo
postfix-ldap
postfix-postgresql
postfix-bdb
postfix-bdb-debuginfo
postfix-bdb-lmdb-debuginfo
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
Basesystem Module
Server Applications Module
Legacy Module
openSUSE Leap
RecoverPoint for VMs
Dell EMC VxRail Appliance

How to mitigate CVE-2023-32182

Install updates from vendor's website.

postfix - addressed in versions 3.7.3-150500.3.5.1, 3.2.10-3.27.2, 3.5.9-150300.5.12.2
postfix-doc - addressed in versions 3.2.10-3.27.2, 3.5.9-150300.5.12.2, 3.7.3-150500.3.5.1
postfix-mysql-debuginfo - addressed in versions 3.2.10-3.27.2, 3.5.9-150300.5.12.2, 3.7.3-150500.3.5.1
postfix-mysql - addressed in versions 3.2.10-3.27.2, 3.5.9-150300.5.12.2, 3.7.3-150500.3.5.1
postfix-debuginfo - addressed in versions 3.2.10-3.27.2, 3.5.9-150300.5.12.2, 3.7.3-150500.3.5.1
postfix-devel - addressed in versions 3.2.10-3.27.2, 3.5.9-150300.5.12.2, 3.7.3-150500.3.5.1
postfix-debugsource - addressed in versions 3.2.10-3.27.2, 3.5.9-150300.5.12.2, 3.7.3-150500.3.5.1
postfix-lmdb - update to 3.4.7-150200.3.12.2
postfix-lmdb-debuginfo - update to 3.4.7-150200.3.12.2
postfix-ldap-debuginfo - addressed in versions 3.5.9-150300.5.12.2, 3.7.3-150500.3.5.1
postfix-bdb-lmdb - addressed in versions 3.5.9-150300.5.12.2, 3.7.3-150500.3.5.1
postfix-bdb-debugsource - addressed in versions 3.5.9-150300.5.12.2, 3.7.3-150500.3.5.1
postfix-postgresql-debuginfo - addressed in versions 3.5.9-150300.5.12.2, 3.7.3-150500.3.5.1
postfix-ldap - addressed in versions 3.5.9-150300.5.12.2, 3.7.3-150500.3.5.1
postfix-postgresql - addressed in versions 3.5.9-150300.5.12.2, 3.7.3-150500.3.5.1
postfix-bdb - addressed in versions 3.5.9-150300.5.12.2, 3.7.3-150500.3.5.1
postfix-bdb-debuginfo - addressed in versions 3.5.9-150300.5.12.2, 3.7.3-150500.3.5.1
postfix-bdb-lmdb-debuginfo - addressed in versions 3.5.9-150300.5.12.2, 3.7.3-150500.3.5.1
RecoverPoint for VMs - update to 6.0.SP1.P1
Dell EMC VxRail Appliance - update to 8.0.120

External References

Related Security Bulletins