vendor:
Postfix
by:
deadbeat
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Postfix
Affected Version From: 1.1.12
Affected Version To: 1.1.12
Patch Exists: YES
Related CWE: CAN-2003-0468, CAN-2003-0540
CPE: postfix
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Redhat 9.0, Redhat 8.0, Mandrake 9.0
2003
Remote Dos for postfix version 1.1.12
This exploit can be used to lock up Postfix 1.1.12 and below by connecting to an SMTP host and sending a malformed envelope address. This can cause the queue manager to lock up until the message is removed manually from the queue, and can also lock the SMTP listener, resulting in a denial of service.
Mitigation:
Upgrade to a version of Postfix that is not vulnerable to this exploit.