PT-2003-1643 · Postfix · Postfix
Michal Zalewski
·
Publicado
2003-08-05
·
Atualizado
2017-10-11
·
CVE-2003-0468
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
Postfix versions 1.1.11 and earlier
Description:
The issue allows remote attackers to use Postfix to conduct scans or attacks of other hosts. This is achieved by sending an email address to the local host containing the target IP address and service name followed by a "!" string. As a result, Postfix attempts to use SMTP to communicate with the target on the associated port.
Recommendations:
For Postfix versions 1.1.11 and earlier, consider updating to a newer version to mitigate the risk of exploitation. As a temporary workaround, consider restricting access to the SMTP service to minimize the risk of unauthorized use.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Postfix