{"id":"openSUSE-SU-2021:0669-1","summary":"Security update for postsrsd","details":"This update for postsrsd fixes the following issues:\n\nUpdate to release 1.11 [boo#1180251]\n\n* Drop group privileges as well as user privileges\n* Fixed: The subprocess that talks to Postfix could be caused\n  to hang with a very long email address. [CVE-2020-35573]\n\nUpdate to release 1.6\n\n* Fix endianness issue with SHA-1 implementation\n* Add dual stack support\n* Make SRS separator configurable\n\nThis update was imported from the openSUSE:Leap:15.2:Update update project.","modified":"2026-02-04T03:53:11.842170Z","published":"2021-05-04T22:05:31Z","related":["CVE-2020-35573"],"upstream":["CVE-2020-35573"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RCKOE2BLGX23FISPQ3WVS2WYO4VR5IUX/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1180251"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-35573"}],"affected":[{"package":{"name":"postsrsd","ecosystem":"SUSE:Package Hub 15 SP2","purl":"pkg:rpm/suse/postsrsd&distro=SUSE%20Package%20Hub%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.11-bp152.4.3.1"}]}],"ecosystem_specific":{"binaries":[{"postsrsd":"1.11-bp152.4.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:0669-1.json"}}],"schema_version":"1.7.3"}