Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Debian 3.0 DSA 363-1: Critical Postfix Denial of Service Alert

debian
Calendar Grey August 3, 2003
Scroller Debian
Multiple security flaws identified in postfix require immediate updates for Debian systems to prevent potential disruptions in service.
There are multiple vulnerabiilities in postfix.

Summary

The postfix mail transport agent in Debian 3.0 contains two
vulnerabilities:

CAN-2003-0468: Postfix would allow an attacker to bounce-scan private
networks or use the daemon as a DDoS tool by forcing the daemon to
connect to an arbitrary service at an arbitrary IP address and
either receiving a bounce message or observing queue operations to
infer the status of the delivery attempt.

CAN-2003-0540: a malformed envelope address can 1) cause the queue
manager to lock up until an entry is removed from the queue and 2)
lock up the smtp listener leading to a denial of service

For the current stable distribution (woody) these problems have been
fixed in version 1.1.11-0.woody3.

For the unstable distribution (sid) these problems will be fixed soon.

We recommend that you update your postfix package.

Upgrade Instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sourc...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: postfix

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.