PT-2005-1415 · Postfix+1 · Postfix+1
Jean-Samuel Reynaud
·
Published
2005-02-10
·
Updated
2017-10-11
·
CVE-2005-0337
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Postfix version 2.1.3
Description
The issue allows remote attackers to bypass e-mail restrictions and perform mail relaying by sending mail to an IPv6 hostname, when /proc/net/if inet6 is not available and permit mx backup is enabled in smtpd recipient restrictions.
Recommendations
For Postfix version 2.1.3, consider disabling the permit mx backup option in smtpd recipient restrictions as a temporary workaround to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Postfix
Red Hat