Candidate: CVE-2019-16791 PublicDate: 2020-01-22 02:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16791 https://github.com/Snawoot/postfix-mta-sts-resolver/security/advisories/GHSA-h92m-42h4-82f6 https://gist.github.com/Snawoot/b9da85d6b26dea5460673b29df1adc6b Description: In postfix-mta-sts-resolver before 0.5.1, All users can receive incorrect response from daemon under rare conditions, rendering downgrade of effective STS policy. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H [5.9 MEDIUM] Patches_postfix-mta-sts-resolver: upstream_postfix-mta-sts-resolver: not-affected (debian: Fixed before initial upload) precise/esm_postfix-mta-sts-resolver: DNE trusty_postfix-mta-sts-resolver: ignored (out of standard support) trusty/esm_postfix-mta-sts-resolver: DNE xenial_postfix-mta-sts-resolver: DNE bionic_postfix-mta-sts-resolver: DNE eoan_postfix-mta-sts-resolver: DNE focal_postfix-mta-sts-resolver: needs-triage groovy_postfix-mta-sts-resolver: ignored (reached end-of-life) hirsute_postfix-mta-sts-resolver: ignored (reached end-of-life) impish_postfix-mta-sts-resolver: needs-triage jammy_postfix-mta-sts-resolver: needs-triage devel_postfix-mta-sts-resolver: needs-triage