CVE Vulnerabilities

CVE-2003-0540

Published: Aug 27, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the .! string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a .! string, which causes an instance of the SMTP listener to lock up.

Affected Software

NameVendorStart VersionEnd Version
PostfixWietse_venema1.0.21 (including)1.0.21 (including)
PostfixWietse_venema1.1.11 (including)1.1.11 (including)
PostfixWietse_venema1.1.12 (including)1.1.12 (including)
PostfixWietse_venema1999-09-06 (including)1999-09-06 (including)
PostfixWietse_venema1999-12-31 (including)1999-12-31 (including)
PostfixWietse_venema2000-02-28 (including)2000-02-28 (including)
PostfixWietse_venema2001-11-15 (including)2001-11-15 (including)
LinuxConectiva7.0 (including)7.0 (including)
LinuxConectiva8.0 (including)8.0 (including)
Red Hat Linux 7.3RedHat*
Red Hat Linux 8.0RedHat*
Red Hat Linux 9RedHat*

References