The address parser code in Postfix 1.1.12 and previous versions allows remote malicious users to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
conectiva linux 7.0 |
||
conectiva linux 8.0 |
||
wietse venema postfix 1.0.21 |
||
wietse venema postfix 1.1.11 |
||
wietse venema postfix 1.1.12 |
||
wietse venema postfix 2000-02-28 |
||
wietse venema postfix 2001-11-15 |
||
wietse venema postfix 1999-09-06 |
||
wietse venema postfix 1999-12-31 |