Description
The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T01:58:10.982Z
Reserved: 2003-07-14T00:00:00.000Z
Link: CVE-2003-0540
No data.
Status : Modified
Published: 2003-08-27T04:00:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2003-0540
OpenCVE Enrichment
No data.
Weaknesses