CVE-2003-0540
EPSS 21.3%
描述
The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.
如何修補 CVE-2003-0540
要修補 CVE-2003-0540,請將受影響套件升級到下列已修補版本。
- Debian/postfix—升級至 1.1.12 或更新版本
CVE-2003-0540 正在被利用嗎?
中等 — EPSS 為 21.3%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 1.1.12