{"id":"CVE-2019-16791","details":"In postfix-mta-sts-resolver before 0.5.1, All users can receive incorrect response from daemon under rare conditions, rendering downgrade of effective STS policy.","aliases":["GHSA-h92m-42h4-82f6","PYSEC-2020-174"],"modified":"2026-07-09T02:48:50.499585Z","published":"2020-01-22T02:15:11.367Z","references":[{"type":"FIX","url":"https://gist.github.com/Snawoot/b9da85d6b26dea5460673b29df1adc6b"},{"type":"FIX","url":"https://github.com/Snawoot/postfix-mta-sts-resolver/security/advisories/GHSA-h92m-42h4-82f6"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/snawoot/postfix-mta-sts-resolver","events":[{"introduced":"0"},{"fixed":"072601f106a152b4c2278dd963eadb51ee62b7bf"}],"database_specific":{"cpe":"cpe:2.3:a:postfix-mta-sts-resolver_project:postfix-mta-sts-resolver:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.5.1"}],"source":"CPE_RANGE"}}],"versions":["v0.5.0","v0.4.5","v0.4.4","v0.4.3","v0.4.2","v0.4.1","v0.4.0","v0.3.0","v0.2.9","v0.2.8","v0.2.7","v0.2.5","v0.2.4","v0.2.3","v0.2.2","v0.2.0","v0.1.5","v0.1.4","v0.1.3","v0.1.2","v0.1.1","v0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-16791.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}