Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 249275 - mail-filter/MailScanner <4.73.3-1 Clean() Infinite Loop Vulnerability
Summary: mail-filter/MailScanner <4.73.3-1 Clean() Infinite Loop Vulnerability
Status: RESOLVED DUPLICATE of bug 253657
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/32915/
Whiteboard: ~3 [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-11-29 17:12 UTC by Robert Buchholz (RETIRED)
Modified: 2009-01-08 23:57 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2008-11-29 17:12:30 UTC
A vulnerability has been reported in MailScanner, which potentially
can be exploited by malicious people to cause a DoS (Denial of
Service).

The vulnerability is caused due to an error within the "Clean()"
function in Message.pm. This can be exploited to trigger the
execution of an infinite loop via a specially crafted email message
and e.g. consume large amounts of CPU.

NOTE: A successful exploitation will not result in the immediate
inability to process email.

The vulnerability is reported in versions prior to 4.73.3-1.

SOLUTION:
Fixed in beta version 4.73.3-1.

PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor.

ORIGINAL ADVISORY:
http://mailscanner.info/index.html
http://www.mailscanner.info/ChangeLog
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2008-11-29 17:13:35 UTC
[ Text by Secunia, forgot to note ]
Comment 2 Stefan Behte (RETIRED) gentoo-dev Security 2009-01-08 23:57:25 UTC
Will be handled in #253657, too.

*** This bug has been marked as a duplicate of bug 253657 ***