vendor:
Postfix
by:
Albert Sellarès and Marc Morata Fité
7.8
CVSS
HIGH
Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902
20
CWE
Product Name: Postfix
Affected Version From: 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902
Affected Version To: 2.4.9, 2.5.5, and 2.6-20080902
Patch Exists: YES
Related CWE: CVE-2008-3889 & CVE-2008-4042
CPE: 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux 2.6
2008
Exploit for Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902
This Proof of concept creates a pipe and adds it in the postfix's epoll file descriptor. When the pipe is added, an endless loop will launch lots of events to the local and master postfix processes. This will slowdown de system a lot.
Mitigation:
Upgrade to Postfix version 2.4.9, 2.5.5, and 2.6-20080902 or later