PT-2002-2112 · Amavis · Amavis

Published

2002-10-04

·

Updated

2016-10-18

·

CVE-2002-1109

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: AMaViS shell script version 0.2.1 and earlier
Description: The issue allows users to cause a denial of service, specifically CPU consumption, by providing a malformed TAR file. This could potentially be achieved via an incorrect file size parameter.
Recommendations: For AMaViS shell script version 0.2.1 and earlier, consider validating TAR file formats to prevent malformed files from being processed, and implement measures to limit CPU consumption in case of incorrect file size parameters. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1109

Affected Products

Amavis