Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 249275

Summary: mail-filter/MailScanner <4.73.3-1 Clean() Infinite Loop Vulnerability
Product: Gentoo Security Reporter: Robert Buchholz (RETIRED) <rbu>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED DUPLICATE    
Severity: trivial CC: jokey, remspoor
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://secunia.com/advisories/32915/
Whiteboard: ~3 [ebuild]
Package list:
Runtime testing required: ---

Description Robert Buchholz (RETIRED) gentoo-dev 2008-11-29 17:12:30 UTC
A vulnerability has been reported in MailScanner, which potentially
can be exploited by malicious people to cause a DoS (Denial of
Service).

The vulnerability is caused due to an error within the "Clean()"
function in Message.pm. This can be exploited to trigger the
execution of an infinite loop via a specially crafted email message
and e.g. consume large amounts of CPU.

NOTE: A successful exploitation will not result in the immediate
inability to process email.

The vulnerability is reported in versions prior to 4.73.3-1.

SOLUTION:
Fixed in beta version 4.73.3-1.

PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor.

ORIGINAL ADVISORY:
http://mailscanner.info/index.html
http://www.mailscanner.info/ChangeLog
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2008-11-29 17:13:35 UTC
[ Text by Secunia, forgot to note ]
Comment 2 Stefan Behte (RETIRED) gentoo-dev Security 2009-01-08 23:57:25 UTC
Will be handled in #253657, too.

*** This bug has been marked as a duplicate of bug 253657 ***