PT-2021-4261 · Postsrsd+1 · Postsrsd+1

Mateusz Jończyk

·

Published

2021-06-28

·

Updated

2021-09-20

·

CVE-2021-35525

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions PostSRSd versions prior to 1.11
Description The issue is related to the incorrect handling of certain long data fields by the PostSRSd daemon in Postfix, which can lead to a denial of service (subprocess hang) when Postfix sends specific long data fields, such as multiple concatenated email addresses. The maintainer of PostSRSd acknowledges this as a security bug, although they question the reliability of triggering this condition by an external attacker.
Recommendations For PostSRSd versions prior to 1.11, update to version 1.11 or later to resolve the issue. As a temporary workaround, consider restricting the use of long data fields in Postfix to minimize the risk of exploitation.

Fix

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04869
CVE-2021-35525

Affected Products

Postsrsd
Postfix