Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
downgrade of effective Strict Transport Security (STS) policy in postfix-mta-sts-resolver
Vulnerability Description
In postfix-mta-sts-resolver before 0.5.1, All users can receive incorrect response from daemon under rare conditions, rendering downgrade of effective STS policy.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N
Vulnerability Type
在会话协商时选择低安全性的算法(算法降级)
Vulnerability Title
postfix-mta-sts-resolver 安全漏洞
Vulnerability Description
Postfix是一款开源的邮件传输代理。 postfix-mta-sts-resolver 0.5.1之前版本中存在安全漏洞。攻击者可利用该漏洞对有效的STS策略进行降级。
CVSS Information
N/A
Vulnerability Type
N/A