CVE-2010-3292
The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or digital signature checking which could allow an attacker to replace certain configuration files (e.g., phishing…
Does this matter?
Lower severity and a low EPSS score (0.17%). Track it; it rarely justifies an emergency change on its own.
Description
The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or digital signature checking which could allow an attacker to replace certain configuration files (e.g., phishing whitelist) via dns/packet spoofing.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.17% probability · 6th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-311
- Affected
- mailscanner/mailscanner
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/cve-2010-3292Broken Link
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=596396Mailing List, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2010-3292Third Party Advisory
- https://www.openwall.com/lists/oss-security/2010/09/13/9Mailing List, Third Party Advisory
- https://access.redhat.com/security/cve/cve-2010-3292Broken Link
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=596396Mailing List, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2010-3292Third Party Advisory
- https://www.openwall.com/lists/oss-security/2010/09/13/9Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.