Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Buffer overflow in the w_read function in sockets.c in Cami Sardinha and Nigel Kukard policyd before 1.81 for Postfix allows remote attackers to cause a denial of service and possibly execute arbitrary code via long SMTP commands. NOTE: some of these details are obtained from third party information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
policyd W_Read函数远程缓冲区溢出漏洞
Vulnerability Description
policyd是基于APF server技术的开源策略服务器,专门针对Postfix MTA,可实现SPF、Greylist、MSBL、自定义黑/白名单及并发统计等高级功能。 policyd的sockets.c文件中的w_read()函数中存在缓冲区溢出漏洞,远程攻击者可能利用此漏洞控制服务器。 如果远程攻击者向有漏洞的系统发送了超长的SMTP命令的话,就可以触发这个溢出,导致拒绝服务或执行任意指令。
CVSS Information
N/A
Vulnerability Type
N/A