PT-2005-3012 · Sendmail+1 · Sendmail+1

Damian Menscher

·

Published

2005-06-29

·

Updated

2008-09-05

·

CVE-2005-2070

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: ClamAV Mail fILTER (clamav-milter) versions 0.84 through 0.85d
Description: The issue allows remote attackers to cause a denial of service by keeping an open connection, which prevents ClamAV from reloading, specifically when used in Sendmail using long timeouts.
Recommendations: For versions 0.84 through 0.85d, consider restricting the use of long timeouts in Sendmail or implement measures to limit the duration of open connections to mitigate the risk of denial of service.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2070
DSA-737-1
DTSA-3-1

Affected Products

Clamav
Sendmail