Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.
| Vendor | Product | Versions |
|---|---|---|
| postfix | postfix | 2.3, 3.9, 3.10, 3.8.15, 3.9.9, 3.10.8 |
Updated affected versions to 3.8.15, 3.9.9, and 3.10.8, changed severity to MEDIUM, and noted that the vulnerability is actively exploited.
Initial creation