5.3
CVSSv3

CVE-2021-35525

Published: 28/06/2021 Updated: 20/09/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

PostSRSd prior to 1.11 allows a denial of service (subprocess hang) if Postfix sends certain long data fields such as multiple concatenated email addresses. NOTE: the PostSRSd maintainer acknowledges "theoretically, this error should never occur ... I'm not sure if there's a reliable way to trigger this condition by an external attacker, but it is a security bug in PostSRSd nevertheless."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

postsrsd project postsrsd

Vendor Advisories

Debian Bug report logs - #990439 postsrsd: CVE-2021-35525 Package: src:postsrsd; Maintainer for src:postsrsd is Oxan van Leeuwen <oxan@oxanvanleeuwennl>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 29 Jun 2021 05:45:02 UTC Severity: important Tags: security, upstream Found in version postsrsd/1 ...