|
|
Vulnerability Assessment & Network Security Forums |
|||||||||
|
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> Mandrake Local Security Checks >> MDKSA-2003:081: postfix Vulnerability Assessment Details
|
MDKSA-2003:081: postfix |
||
|
Check for the version of the postfix package Detailed Explanation for this Vulnerability Assessment The remote host is missing the patch for the advisory MDKSA-2003:081 (postfix). Two vulnerabilities were discovered in the postfix MTA by Michal Zalewski. Versions prior to 1.1.12 would permit a possible hacker to bounce- scan private networks or use the daemon as a DDoS (Distributed Denial of Service) tool by forcing the daemon to connect to an arbitrary service at an arbitrary IP address and receiving either a bounce message or by timing. As well, versions prior to 1.1.12 have a bug where a malformed envelope address can cause the queue manager to lock up until an entry is removed from the queue and also lock up the SMTP listener leading to a DoS. Postfix version 1.1.13 corrects these issues. The provided packages have been patched to fix the vulnerabilities. Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2003:081 Network Security Threat Level: High Networks Security ID: 8361, 8362 Vulnerability Assessment Copyright: This script is Copyright (C) 2004 Tenable Network Security |
||
|
KVM Switch Boxes, Cables |
|
||
|
No Discussions have been posted on this vulnerability. |