The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the .! string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a .! string, which causes an instance of the SMTP listener to lock up.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Postfix | Wietse_venema | 1.0.21 (including) | 1.0.21 (including) |
Postfix | Wietse_venema | 1.1.11 (including) | 1.1.11 (including) |
Postfix | Wietse_venema | 1.1.12 (including) | 1.1.12 (including) |
Postfix | Wietse_venema | 1999-09-06 (including) | 1999-09-06 (including) |
Postfix | Wietse_venema | 1999-12-31 (including) | 1999-12-31 (including) |
Postfix | Wietse_venema | 2000-02-28 (including) | 2000-02-28 (including) |
Postfix | Wietse_venema | 2001-11-15 (including) | 2001-11-15 (including) |
Linux | Conectiva | 7.0 (including) | 7.0 (including) |
Linux | Conectiva | 8.0 (including) | 8.0 (including) |
Red Hat Linux 7.3 | RedHat | * | |
Red Hat Linux 8.0 | RedHat | * | |
Red Hat Linux 9 | RedHat | * |