漏洞信息详情
QMail RCPT服务拒绝漏洞
- CNNVD编号:CNNVD-199706-001
- 危害等级: 低危
- CVE编号:
CVE-1999-0144
- 漏洞类型:
其他
- 发布时间:
1997-06-01
- 威胁类型:
本地
- 更新时间:
2005-10-20
- 厂 商:
qmail - 漏洞来源:
This behaviour was… -
漏洞简介
Qmail存在漏洞。通过指定大量带有RCPT命令的接受者导致服务拒绝。
漏洞公告
Setting user resource limits on the server process will prevent Qmail from allocating enough memory to cause a denial of service.
The following command will set the maximum amount of memory processes can allocate in the heap to 1 MB.
‘ulimit -d 1024’.
If placed in the init scripts, the limit will be put in place whenever the system intializes.
This information was supplied by Dan Bernstein
参考网址
来源: XF
名称: qmail-rcpt
链接:http://xforce.iss.net/static/208.php
来源: BID
名称: 2237
链接:http://www.securityfocus.com/bid/2237
来源: www.ornl.gov
链接:http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html
来源: cr.yp.to
链接:http://cr.yp.to/qmail/venema.html
来源: BUGTRAQ
名称: 19970612 Re: Denial of service (qmail-smtpd)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=87602558319029&w=2
来源: BUGTRAQ
名称: 19970612 qmail-dos-2.c, another denial of service attack
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=87602558319024&w=2