#VU110624 Input validation error in Postfix - CVE-2003-0468

 

#VU110624 Input validation error in Postfix - CVE-2003-0468

Published: June 8, 2025


Vulnerability identifier: #VU110624
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:L/E:U/U:Green
CVE-ID: CVE-2003-0468
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Postfix
Software vendor:
Postfix.org

Description

The vulnerability allows a remote attacker to perform DDoS attacks against third-party systems.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can abuse Postfix to conduct "bounce scans" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a "!" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port.


Remediation

Install updates from vendor's website.

External links