5
CVSSv2

CVE-2003-0468

Published: 27/08/2003 Updated: 11/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Postfix 1.1.11 and previous versions allows remote malicious users to use Postfix to conduct "bounce scans" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a "!" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port.

Vulnerable Product Search on Vulmon Subscribe to Product

wietse venema postfix 2000-02-28

wietse venema postfix 2001-11-15

conectiva linux 7.0

conectiva linux 8.0

wietse venema postfix 1999-09-06

wietse venema postfix 1999-12-31

wietse venema postfix 1.0.21

wietse venema postfix 1.1.11

Vendor Advisories

The postfix mail transport agent in Debian 30 contains two vulnerabilities: CAN-2003-0468: Postfix would allow an attacker to bounce-scan private networks or use the daemon as a DDoS tool by forcing the daemon to connect to an arbitrary service at an arbitrary IP address and either receiving a bounce message or observing queue operations to ...