{"api_version":"1","generated_at":"2026-07-23T06:54:35+00:00","cve":"CVE-2003-0468","urls":{"html":"https://cve.report/CVE-2003-0468","api":"https://cve.report/api/cve/CVE-2003-0468.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-0468","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-0468"},"summary":{"title":"CVE-2003-0468","description":"Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct \"bounce scans\" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a \"!\" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port.","state":"PUBLISHED","assigner":"mitre","published_at":"2003-08-27 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/9433","name":"http://secunia.com/advisories/9433","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - Postfix DoS and Bounce Scan Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.novell.com/linux/security/advisories/2003_033_postfix.html","name":"http://www.novell.com/linux/security/advisories/2003_033_postfix.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"NOVELL: Broken Link - 404 Error Pages","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2003-251.html","name":"http://www.redhat.com/support/errata/RHSA-2003-251.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=106001525130257&w=2","name":"http://marc.info/?l=bugtraq&m=106001525130257&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Postfix 1.1.12 remote DoS / Postfix 1.1.11 bounce scanning' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2003:081","name":"http://www.mandriva.com/security/advisories?name=MDKSA-2003:081","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Advisories - Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000717","name":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000717","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Home - Conectiva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/8333","name":"http://www.securityfocus.com/bid/8333","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Multiple Postfix Denial of Service Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A522","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A522","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2003/dsa-363","name":"http://www.debian.org/security/2003/dsa-363","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Debian -- Security Information -- DSA-363-1 postfix","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-0468","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-0468","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"468","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"conectiva","cpe5":"linux","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"468","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"conectiva","cpe5":"linux","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"468","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wietse_venema","cpe5":"postfix","cpe6":"1.0.21","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"468","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wietse_venema","cpe5":"postfix","cpe6":"1.1.11","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"468","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wietse_venema","cpe5":"postfix","cpe6":"1999-09-06","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"468","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wietse_venema","cpe5":"postfix","cpe6":"1999-12-31","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"468","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wietse_venema","cpe5":"postfix","cpe6":"2000-02-28","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"468","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wietse_venema","cpe5":"postfix","cpe6":"2001-11-15","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:58:10.240Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"CLA-2003:717","tags":["vendor-advisory","x_refsource_CONECTIVA","x_transferred"],"url":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000717"},{"name":"8333","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/8333"},{"name":"MDKSA-2003:081","tags":["vendor-advisory","x_refsource_MANDRAKE","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2003:081"},{"name":"RHSA-2003:251","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2003-251.html"},{"name":"DSA-363","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2003/dsa-363"},{"name":"20030804 Postfix 1.1.12 remote DoS / Postfix 1.1.11 bounce scanning","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=106001525130257&w=2"},{"name":"SuSE-SA:2003:033","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://www.novell.com/linux/security/advisories/2003_033_postfix.html"},{"name":"9433","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/9433"},{"name":"oval:org.mitre.oval:def:522","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A522"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-08-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct \"bounce scans\" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a \"!\" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-10-10T00:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"CLA-2003:717","tags":["vendor-advisory","x_refsource_CONECTIVA"],"url":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000717"},{"name":"8333","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/8333"},{"name":"MDKSA-2003:081","tags":["vendor-advisory","x_refsource_MANDRAKE"],"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2003:081"},{"name":"RHSA-2003:251","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2003-251.html"},{"name":"DSA-363","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2003/dsa-363"},{"name":"20030804 Postfix 1.1.12 remote DoS / Postfix 1.1.11 bounce scanning","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=106001525130257&w=2"},{"name":"SuSE-SA:2003:033","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://www.novell.com/linux/security/advisories/2003_033_postfix.html"},{"name":"9433","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/9433"},{"name":"oval:org.mitre.oval:def:522","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A522"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-0468","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct \"bounce scans\" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a \"!\" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"CLA-2003:717","refsource":"CONECTIVA","url":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000717"},{"name":"8333","refsource":"BID","url":"http://www.securityfocus.com/bid/8333"},{"name":"MDKSA-2003:081","refsource":"MANDRAKE","url":"http://www.mandriva.com/security/advisories?name=MDKSA-2003:081"},{"name":"RHSA-2003:251","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2003-251.html"},{"name":"DSA-363","refsource":"DEBIAN","url":"http://www.debian.org/security/2003/dsa-363"},{"name":"20030804 Postfix 1.1.12 remote DoS / Postfix 1.1.11 bounce scanning","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=106001525130257&w=2"},{"name":"SuSE-SA:2003:033","refsource":"SUSE","url":"http://www.novell.com/linux/security/advisories/2003_033_postfix.html"},{"name":"9433","refsource":"SECUNIA","url":"http://secunia.com/advisories/9433"},{"name":"oval:org.mitre.oval:def:522","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A522"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-0468","datePublished":"2003-08-05T04:00:00.000Z","dateReserved":"2003-06-26T00:00:00.000Z","dateUpdated":"2024-08-08T01:58:10.240Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-08-27 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wietse_venema:postfix:1.0.21:*:*:*:*:*:*:*","matchCriteriaId":"F8C70650-45F8-42F1-863E-C14CFD27986D"},{"vulnerable":true,"criteria":"cpe:2.3:a:wietse_venema:postfix:1.1.11:*:*:*:*:*:*:*","matchCriteriaId":"6886742C-C8CF-4DE8-812C-30CB19984329"},{"vulnerable":true,"criteria":"cpe:2.3:a:wietse_venema:postfix:1999-09-06:*:*:*:*:*:*:*","matchCriteriaId":"D8F498EC-BAB8-44E9-A1E9-F5FE59D969E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:wietse_venema:postfix:1999-12-31:*:*:*:*:*:*:*","matchCriteriaId":"3AC09670-77D3-40B7-BD0A-2F447FAB272E"},{"vulnerable":true,"criteria":"cpe:2.3:a:wietse_venema:postfix:2000-02-28:*:*:*:*:*:*:*","matchCriteriaId":"711ECD8D-66D7-414E-B509-9F10A93FCED8"},{"vulnerable":true,"criteria":"cpe:2.3:a:wietse_venema:postfix:2001-11-15:*:*:*:*:*:*:*","matchCriteriaId":"0C6E6C91-AE96-481F-92F5-C56F45ABE8E3"},{"vulnerable":true,"criteria":"cpe:2.3:o:conectiva:linux:7.0:*:*:*:*:*:*:*","matchCriteriaId":"97177EF7-8FC4-4D4D-A8D9-3628AA0035FB"},{"vulnerable":true,"criteria":"cpe:2.3:o:conectiva:linux:8.0:*:*:*:*:*:*:*","matchCriteriaId":"CD14661C-E3BE-44DF-BC8D-294322BF23EA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"468","Ordinal":"1","Title":"CVE-2003-0468","CVE":"CVE-2003-0468","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"468","Ordinal":"1","NoteData":"Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct \"bounce scans\" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a \"!\" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port.","Type":"Description","Title":"CVE-2003-0468"},{"CveYear":"2003","CveId":"468","Ordinal":"2","NoteData":"2003-08-05","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"468","Ordinal":"3","NoteData":"2017-10-09","Type":"Other","Title":"Modified"}]}}}