Qmail RCPT denial of service attack

Risk Level: Medium risk vulnerability  Medium

Check or Attack Name: qmailrecipient

Platforms: Qmail: 1.01 and earlier
Description:

A vulnerability exists within Qmail that could render the server unusable. By sending a RCPT command to the server with an extremely large number of recipients it is possible to cause the Qmail server to exhaust all the system's resources and crash.

Remedy:

Upgrade your version of Qmail to 1.02 or later.

References:

QMAIL Mailing List, qmail-dos-2.c, another denial of service attack, http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/msg00322.html

Qmail Home Page, qmail: a replacement for sendmail, http://www.qmail.org/top.html


X-Force Logo
Know Your Risks