PT-2005-3012 · Sendmail+1 · Sendmail+1
Damian Menscher
·
Published
2005-06-29
·
Updated
2008-09-05
·
CVE-2005-2070
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
ClamAV Mail fILTER (clamav-milter) versions 0.84 through 0.85d
Description:
The issue allows remote attackers to cause a denial of service by keeping an open connection, which prevents ClamAV from reloading, specifically when used in Sendmail using long timeouts.
Recommendations:
For versions 0.84 through 0.85d, consider restricting the use of long timeouts in Sendmail or implement measures to limit the duration of open connections to mitigate the risk of denial of service.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Clamav
Sendmail