search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Postfix vulnerable to DoS by supplying a remote SMTP listener with a malformed envelope address

Vulnerability Note VU#895508

Original Release Date: 2003-08-11 | Last Revised: 2003-08-18

Overview

A denial-of-service vulnerability exists in all versions of Postfix prior to 2.0. This vulnerability may allow a remote attacker to cause mail service interruption.

Description

Postfix is a very popular mail transfer agent (MTA). Michal Zalewski has discovered a denial-of-service vulnerability in Postfix. According to Michal, the vulnerability exists in a portion of code responsible for address parsing. For further technical details, please see Michal's announcement.

Note that this vulnerability is message-oriented as opposed to connection-oriented. That means that the vulnerability is triggered by the contents of a specially-crafted email message rather than by lower-level network traffic. This is important because an MTA that does not contain the vulnerability may pass the malicious message along to other MTAs that may be protected at the network level. In other words, vulnerable Postfix servers on the interior of a network are still at risk, even if the site's border MTA uses software other than Postfix.

Impact

Postfix will be unable to deliver email.

Solution

Apply a patch from your vendor.

Workarounds

Based on feedback from the author of Postfix, if recipient name checking is turned on (Recipient name checking is turned off by default in version 1.1.11), mail for <nonexistent@[127.0.0.1]> is rejected.

Vendor Information

895508
 

View all 12 vendors View less vendors


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This vulnerability was discovered by Michal Zalewski. The CERT/CC thanks Michal for providing information upon which this document is based. We also thank the author of Postfix, Wietse Venema, for his help in understanding the vulnerability.

This document was written by Ian A Finlay.

Other Information

CVE IDs: CVE-2003-0540
Severity Metric: 8.10
Date Public: 2003-08-03
Date First Published: 2003-08-11
Date Last Updated: 2003-08-18 13:09 UTC
Document Revision: 11

Sponsored by CISA.