CVE-2005-0337

7 documents7 sources
Severity
7.5HIGH
EPSS
0.8%
top 25.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 2
Latest updateMay 1

Description

Postfix 2.1.3, when /proc/net/if_inet6 is not available and permit_mx_backup is enabled in smtpd_recipient_restrictions, allows remote attackers to bypass e-mail restrictions and perform mail relaying by sending mail to an IPv6 hostname.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages4 packages

Debianpostfix< 2.1.4-5+3
NVDsuse/suse_linux6 versions+5

Also affects: Enterprise Linux 4.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5rxq-6r3q-5xj6: Postfix 22022-05-01
OSV
CVE-2005-0337: Postfix 22005-05-02
CVEList
CVE-2005-0337: Postfix 22005-02-10

📋Vendor Advisories

2
Red Hat
security flaw2005-01-31
Debian
CVE-2005-0337: postfix - Postfix 2.1.3, when /proc/net/if_inet6 is not available and permit_mx_backup is ...2005

💬Community

1
Bugzilla
CVE-2005-0337 security flaw2018-08-16
CVE-2005-0337 (HIGH CVSS 7.5) | Postfix 2.1.3 | cvebase.io