A vulnerability has been reported in MailScanner, which potentially can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an error within the "Clean()" function in Message.pm. This can be exploited to trigger the execution of an infinite loop via a specially crafted email message and e.g. consume large amounts of CPU. NOTE: A successful exploitation will not result in the immediate inability to process email. The vulnerability is reported in versions prior to 4.73.3-1. SOLUTION: Fixed in beta version 4.73.3-1. PROVIDED AND/OR DISCOVERED BY: Reported by the vendor. ORIGINAL ADVISORY: http://mailscanner.info/index.html http://www.mailscanner.info/ChangeLog
[ Text by Secunia, forgot to note ]
Will be handled in #253657, too. *** This bug has been marked as a duplicate of bug 253657 ***