SB2017021308 - Missing Authorization in postfixadmin (Alpine package)
Published: February 13, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Missing Authorization (CVE-ID: CVE-2017-5930)
The vulnerability allows a remote user to bypass authorization process.
The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=561635d29f609b4dff10ce7b23e23069e8b3094e
- https://git.alpinelinux.org/aports/commit/?id=3c14e449a4835e5c55e26e4d3f655d08f3330a68
- https://git.alpinelinux.org/aports/commit/?id=bb544f5eb347cb08f4ba73b1496c936ab8a1d6af
- https://git.alpinelinux.org/aports/commit/?id=cd05f7589eacf39c6a2e716412b1b0c4f32f20f2
- https://git.alpinelinux.org/aports/commit/?id=5c1fabddcbe2a30d67fa87f995b2469b982e9096