peter bassill · operator
$ cve CVE-2003-0540 JSON

CVE-2003-0540 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 21.3% (pctl 98)

Patch early

A public exploit exists.

Description

The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS21.26% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2003-08-27
Last modified2026-06-16

Affected (2)

VendorProduct
conectivalinux
wietse venemapostfix

Public exploits

SourceTitleDate
exploit-dbPostfix 1.1.x - Denial of Service (1)2003-08-04
exploit-dbPostfix 1.1.x - Denial of Service (2)2003-08-04

References

→ the Explorer  ·  watch your stack  ·  NVD