Qmail RCPT denial of service attack |
---|
Risk Level: | Medium | Check or Attack Name: qmailrecipient |
---|---|---|
Platforms: | Qmail: 1.01 and earlier | |
Description: | A vulnerability exists within Qmail that could render the server unusable. By sending a RCPT command to the server with an extremely large number of recipients it is possible to cause the Qmail server to exhaust all the system's resources and crash. |
|
Remedy: | Upgrade your version of Qmail to 1.02 or later. |
|
References: | QMAIL Mailing List, qmail-dos-2.c, another denial of service attack, http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/msg00322.html Qmail Home Page, qmail: a replacement for sendmail, http://www.qmail.org/top.html |
Know Your Risks |