CVE-2019-16791Medium· 6.9▾ Sunlitpostfix-mta-sts-resolver Algorithm Downgrade vulnerability
▾ Sunlit zone — Low / medium · no exploitation signal
impact 38 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.8%
All users of versions prior to 0.5.1 can receive incorrect response from daemon under rare conditions, rendering downgrade of effective STS policy.
Problem has been patched in version 0.5.1
Users may remediate this vulnerability without upgrading by applying these patches to older suppoorted versions.
If you have any questions or comments about this advisory:
postfix-mta-sts-resolver < 0.5.1Upgrade to a patched release:
postfix-mta-sts-resolver 0.5.1