PT-2021-4261 · Postsrsd+1 · Postsrsd+1
Mateusz Jończyk
·
Published
2021-06-28
·
Updated
2021-09-20
·
CVE-2021-35525
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
PostSRSd versions prior to 1.11
Description
The issue is related to the incorrect handling of certain long data fields by the PostSRSd daemon in Postfix, which can lead to a denial of service (subprocess hang) when Postfix sends specific long data fields, such as multiple concatenated email addresses. The maintainer of PostSRSd acknowledges this as a security bug, although they question the reliability of triggering this condition by an external attacker.
Recommendations
For PostSRSd versions prior to 1.11, update to version 1.11 or later to resolve the issue. As a temporary workaround, consider restricting the use of long data fields in Postfix to minimize the risk of exploitation.
Fix
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Postsrsd
Postfix