|
|
Info |
Last Modified |
| 6 months ago |
|
|
|
|
Description |
qmail-smtpd contains a flaw that may allow a remote denial of service. The issue is triggered by sending an email with a large number of recipient addresses. Qmail will attempt to process such message, which will consume all memory on the server host, and will result in loss of availability for this computer.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Denial of Service,
Input Manipulation
Impact:
Loss of Availability
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to version 1.03 or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround: limit amount of memory available to the qmail-smtpd process.
|
|
Products |
|
qmail
 |
1.0.1 |
|
|
|
|
Credit |
- Wietse Venema - wietse
wzv.win.tue.nl -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|