QMail-SMTPD Long SMTP Session Integer Overflow Denial of Service Vulnerability
BID:9432
Info
QMail-SMTPD Long SMTP Session Integer Overflow Denial of Service Vulnerability
| Bugtraq ID: | 9432 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 16 2004 12:00AM |
| Updated: | Jan 16 2004 12:00AM |
| Credit: | The disclosure of this issue has been credited to Georgi Guninski <http://www.guninski.com>. |
| Vulnerable: |
Dan Bernstein QMail 1.0 3 |
| Not Vulnerable: | |
Discussion
QMail-SMTPD Long SMTP Session Integer Overflow Denial of Service Vulnerability
It has been reported that qmail-smtpd may be prone to a remote denial of service vulnerability that may allow an attacker to cause a denial of service condition in the software. An attacker may be able to crash qmail-smtpd via a long SMTP session.
qmail 1.03 running on a Linux platform has been reported to be prone to this issue, however, other versions may be affected as well.
It has been reported that qmail-smtpd may be prone to a remote denial of service vulnerability that may allow an attacker to cause a denial of service condition in the software. An attacker may be able to crash qmail-smtpd via a long SMTP session.
qmail 1.03 running on a Linux platform has been reported to be prone to this issue, however, other versions may be affected as well.
Exploit / POC
QMail-SMTPD Long SMTP Session Integer Overflow Denial of Service Vulnerability
Proof of concept exploit code has been provided. Further information is available in the referenced web pages.
Proof of concept exploit code has been provided. Further information is available in the referenced web pages.
Solution / Fix
QMail-SMTPD Long SMTP Session Integer Overflow Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
QMail-SMTPD Long SMTP Session Integer Overflow Denial of Service Vulnerability
References:
References:
- Lame crash in qmail-smtpd (Georgi Guninski )
- Qmail Homepage (Dan Bernstein)
- Re: Lame crash in qmail-smtpd and memory overwrite according to gdb, yet still q (Scott Gifford
)