In postfix-mta-sts-resolver before 0.5.1, All users can receive incorrect response from daemon under rare conditions, rendering downgrade of effective STS policy.
A protocol or its implementation supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Postfix-mta-sts-resolver | Postfix-mta-sts-resolver_project | * | 0.5.1 (excluding) |
Postfix-mta-sts-resolver | Ubuntu | groovy | * |
Postfix-mta-sts-resolver | Ubuntu | hirsute | * |
Postfix-mta-sts-resolver | Ubuntu | impish | * |
Postfix-mta-sts-resolver | Ubuntu | kinetic | * |
Postfix-mta-sts-resolver | Ubuntu | lunar | * |
Postfix-mta-sts-resolver | Ubuntu | mantic | * |
Postfix-mta-sts-resolver | Ubuntu | trusty | * |