[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-Disclosure] MDKSA-2003:081 - Updated postfix packagesfix remote DoS



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<META NAME="Generator" CONTENT="MS Exchange Server version 6.0.6336.0">
<TITLE>Re: [Full-Disclosure] MDKSA-2003:081 - Updated postfix packages fix remote DoS</TITLE>
</HEAD>
<BODY>
<!-- Converted from text/plain format -->

<P><FONT SIZE=2>On 4 Aug 2003, Mandrake Linux Security Team wrote:<BR>
<BR>
&gt;&nbsp; message or by timing.&nbsp; As well, versions prior to 1.1.12 have a bug<BR>
&gt;&nbsp; where a malformed envelope address can cause the queue manager to<BR>
&gt;&nbsp; lock up until an entry is removed from the queue and also lock up<BR>
&gt;&nbsp; the SMTP listener leading to a DoS.<BR>
<BR>
Prior to 1.1.13.<BR>
<BR>
--<BR>
------------------------- bash$ :(){ :|:&amp;};: --<BR>
&nbsp;Michal Zalewski * [<A HREF="http://lcamtuf.coredump.cx";>http://lcamtuf.coredump.cx</A>]<BR>
&nbsp;&nbsp;&nbsp; Did you know that clones never use mirrors?<BR>
--------------------------- 2003-08-04 10:16 --<BR>
<BR>
_______________________________________________<BR>
Full-Disclosure - We believe in it.<BR>
Charter: <A HREF="http://lists.netsys.com/full-disclosure-charter.html";>http://lists.netsys.com/full-disclosure-charter.html</A><BR>
<BR>
</FONT>
</P>

</BODY>
</HTML>