PT-2002-2112 · Amavis · Amavis
Published
2002-10-04
·
Updated
2016-10-18
·
CVE-2002-1109
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
AMaViS shell script version 0.2.1 and earlier
Description:
The issue allows users to cause a denial of service, specifically CPU consumption, by providing a malformed TAR file. This could potentially be achieved via an incorrect
file size parameter.Recommendations:
For AMaViS shell script version 0.2.1 and earlier, consider validating TAR file formats to prevent malformed files from being processed, and implement measures to limit CPU consumption in case of incorrect file size parameters. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Amavis