Only affects 64 bit platforms with a load of memory. Affects 1.0.2 and 1.0.3. No fixes yet. http://www.guninski.com/where_do_you_want_billg_to_go_today_4.html http://securityfocus.com/bid/13528 http://securityfocus.com/bid/13535 http://securityfocus.com/bid/13536
net-mail please advise.
mail-mta/qmail belongs to qmail-bugs herd.
the first one for sure has come up before and it's retarded ... see Bug 38304
Well the Athlon64 8400+ bit was also making me a bit suspicious to start out with.
They're starting to discuss it on the qmail mailing list. I'll watch what's going on.
Micheal any news on this one?
The discussion on it is here: http://www.gossamer-threads.com/lists/qmail/users/124346 In short, you can DOS a machine with this (and trigger the OOM killer), but ONLY if it has more than 4gb of RAM, and you are running qmail with ulimits above 4gb. Our shipped defaults are 64mb for qmail-smtpd, and 8mb for everything else. Nobody should be running with limits over 512mb even. You'd need a much beefier machine to do the attack in the first place. I'm going to close it as WONTFIX, as it seems the only fix would be to totally re-write qmail, and we are not vulnerable because of our ulimits.
We just have to pay attention to the fact that it seems that ulimits don't work on Mac OS X. If qmail is ever going to (~)ppc-macos, they'll have to work on that.