5

CVE-2003-0540

The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wietse VenemaPostfix Version1.0.21
Wietse VenemaPostfix Version1.1.11
Wietse VenemaPostfix Version1.1.12
Wietse VenemaPostfix Version1999-09-06
Wietse VenemaPostfix Version1999-12-31
Wietse VenemaPostfix Version2000-02-28
Wietse VenemaPostfix Version2001-11-15
ConectivaLinux Version7.0
ConectivaLinux Version8.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 57.49% 0.98
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P