Candidate: CVE-2017-5930 PublicDate: 2017-03-20 16:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5930 http://www.openwall.com/lists/oss-security/2017/02/07/6 Description: The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=854742 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N [2.7 LOW] Patches_postfixadmin: upstream_postfixadmin: released (3.0.2-1) precise_postfixadmin: DNE precise/esm_postfixadmin: DNE trusty_postfixadmin: not-affected (code not present) trusty/esm_postfixadmin: DNE (trusty was not-affected [code not present]) vivid/stable-phone-overlay_postfixadmin: DNE vivid/ubuntu-core_postfixadmin: DNE xenial_postfixadmin: not-affected (code not present) yakkety_postfixadmin: ignored (reached end-of-life) zesty_postfixadmin: ignored (reached end-of-life) artful_postfixadmin: ignored (reached end-of-life) bionic_postfixadmin: not-affected (3.0.2-2) cosmic_postfixadmin: not-affected (3.0.2-2) devel_postfixadmin: not-affected (3.0.2-2)