Courier MTA Long Year Remote Resource Consumption Vulnerability
BID:4908
Info
Courier MTA Long Year Remote Resource Consumption Vulnerability
| Bugtraq ID: | 4908 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 01 2002 12:00AM |
| Updated: | Jun 01 2002 12:00AM |
| Credit: | Vulnerability discovery credited to 3APA3A <[email protected]>. |
| Vulnerable: |
Double Precision Incorporated Courier MTA 0.38.1 |
| Not Vulnerable: | |
Discussion
Courier MTA Long Year Remote Resource Consumption Vulnerability
Courier MTA is a freely available, open source mail transport agent (MTA). It is developed and maintained by Double Precison, Incorporated, and works with various Unix and Linux Operating Systems.
Under some circumstances, it may be possible to cause a denial of service in the MTA. The problem occurs when handling messages by users that contain an excessively large year. This bug could result in resource consumption on the system using the affected MTA, and potentially a denial of service.
Courier MTA is a freely available, open source mail transport agent (MTA). It is developed and maintained by Double Precison, Incorporated, and works with various Unix and Linux Operating Systems.
Under some circumstances, it may be possible to cause a denial of service in the MTA. The problem occurs when handling messages by users that contain an excessively large year. This bug could result in resource consumption on the system using the affected MTA, and potentially a denial of service.
Exploit / POC
Courier MTA Long Year Remote Resource Consumption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Courier MTA Long Year Remote Resource Consumption Vulnerability
Solution:
This vulnerability has reportedly been fixed in the Courier CVS tree.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
This vulnerability has reportedly been fixed in the Courier CVS tree.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Courier MTA Long Year Remote Resource Consumption Vulnerability
References:
References:
- Courier DoS (SECURITY.NNOV)