Multiple Postfix Denial of Service Vulnerabilities
BID:8333
Info
Multiple Postfix Denial of Service Vulnerabilities
| Bugtraq ID: | 8333 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 04 2003 12:00AM |
| Updated: | Aug 04 2003 12:00AM |
| Credit: | Discovery credited to Michal Zalewski. |
| Vulnerable: |
Wietse Venema Postfix 1.1.13 Wietse Venema Postfix 1.1.12 Wietse Venema Postfix 1.1.11 Wietse Venema Postfix 1.0.21 Wietse Venema Postfix 20011115 Wietse Venema Postfix 20010228 Wietse Venema Postfix 19991231 Wietse Venema Postfix 19990906 |
| Not Vulnerable: | |
Solution / Fix
Multiple Postfix Denial of Service Vulnerabilities
Solution:
Conectiva has released advisory CLA-2003:717 with fixes to address this issue. Additional information is available in the referenced advisory. Fixes are linked below.
Debian has issued fixes. See advisory DSA-363-1 listed in the reference section for download locations.
SuSE has released advisory SuSE-SA:2003:033 with fixes to address this issue. See referenced advisory for additional details.
Mandrake has released advisory MDKSA-2003:081 with fixes to address this issue. Additional information is available in the referenced Mandrake Advisory.
Red Hat has released advisory RHSA-2003:251-01. Fix information may be gathered from the referenced advisory.
Guardian Digital has released an advisory (ESA-20030804-019) that provides updates for EnGarde Secure Linux. These updates may be applied automatically with the Guardian Digital WebTool. Please see the attached advisory for instructions on how to apply updates.
Trustix has released an advisory (TSLSA-2003-0029) that addresses this issue. Please see the attached advisory for details on obtaining and applying upgrades.
Wietse Venema Postfix 20011115
Wietse Venema Postfix 19991231
Wietse Venema Postfix 20010228
Solution:
Conectiva has released advisory CLA-2003:717 with fixes to address this issue. Additional information is available in the referenced advisory. Fixes are linked below.
Debian has issued fixes. See advisory DSA-363-1 listed in the reference section for download locations.
SuSE has released advisory SuSE-SA:2003:033 with fixes to address this issue. See referenced advisory for additional details.
Mandrake has released advisory MDKSA-2003:081 with fixes to address this issue. Additional information is available in the referenced Mandrake Advisory.
Red Hat has released advisory RHSA-2003:251-01. Fix information may be gathered from the referenced advisory.
Guardian Digital has released an advisory (ESA-20030804-019) that provides updates for EnGarde Secure Linux. These updates may be applied automatically with the Guardian Digital WebTool. Please see the attached advisory for instructions on how to apply updates.
Trustix has released an advisory (TSLSA-2003-0029) that addresses this issue. Please see the attached advisory for details on obtaining and applying upgrades.
Wietse Venema Postfix 20011115
-
Engarde Secure Linux postfix-20001121-1.0.21.i386.rpm
ftp://ftp.engardelinux.org/pub/engarde/ -
Engarde Secure Linux postfix-20001121-1.0.21.i686.rpm
ftp://ftp.engardelinux.org/pub/engarde/
Wietse Venema Postfix 19991231
-
Trustix postfix-19991231_pl13-4tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/RPMS/postfix-19991231_pl 13-4tr.i586.rpm
Wietse Venema Postfix 20010228
-
Trustix postfix-0.0.20010228.pl08-4tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/RPMS/postfix-0.0.2001022 8.pl08-4tr.i586.rpm
References
Multiple Postfix Denial of Service Vulnerabilities
References:
References:
- Postfix 1.1.12 remote DoS / Postfix 1.1.11 bounce scanning (Michal Zalewski
) - Postfix: old bugs keep coming back ([email protected] (Wietse Venema))