安全公告详情

NS-SA-2025-0159

2025-07-25 16:49:52

简介

moderate: postfix/dav1d security update

严重级别

moderate

主题

An update for postfix/dav1d is now available for NewStart CGSL MAIN 7.02.
NewStart Security has rated this update as having a security impact of moderate. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

postfix:
dav1d:


Security Fix(es):
postfix: A flaw was found in some SMTP server configurations in Postfix. This flaw allows a remote attacker to break out email message data to "smuggle" SMTP commands and send spoofed emails that pass SPF checks. Out of the box, Postfix targets to accommodate older clients with faulty SMTP implementations due to which restrictions are not enforced in the default configuration. Appropriate mitigation strategies are mentioned in the appropriate section below.(CVE-2023-51764)
postfix: bugfix
dav1d: An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.(CVE-2024-1580)
dav1d: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 7.02.03B8.

影响组件

  • postfix
  • dav1d

影响产品

  • CGSL MAIN 7.02

更新包

{"fix":[{"product":"CGSL MAIN 7.02","pkgs":[{"binary":["postfix-3.7.9-1.zncgsl7.3.x86_64.rpm","postfix-perl-scripts-3.7.9-1.zncgsl7.3.x86_64.rpm"],"source":"postfix-3.7.9-1.zncgsl7.3.src.rpm"},{"binary":["libdav1d-1.1.0-1.zncgsl7.3.x86_64.rpm"],"source":"dav1d-1.1.0-1.zncgsl7.3.src.rpm"}]}]}

CVE

参考