Total vulnerabilities in the database
OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c.
Software | From | Fixed in |
---|---|---|
opensmtpd / opensmtpd | - | 6.6.4 |
fedoraproject / fedora | 32 | 32.x |
canonical / ubuntu_linux | 18.04 | 18.04.x |
canonical / ubuntu_linux | 19.10 | 19.10.x |