CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:N/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS
Percentile
53.1%
PostSRSd before 1.11 allows a denial of service (subprocess hang) if
Postfix sends certain long data fields such as multiple concatenated email
addresses. NOTE: the PostSRSd maintainer acknowledges “theoretically, this
error should never occur … I’m not sure if there’s a reliable way to
trigger this condition by an external attacker, but it is a security bug in
PostSRSd nevertheless.”
bugs.gentoo.org/793674
github.com/roehling/postsrsd/commit/077be98d8c8a9847e4ae0c7dc09e7474cbe27db2
github.com/roehling/postsrsd/releases/tag/1.11
launchpad.net/bugs/cve/CVE-2021-35525
nvd.nist.gov/vuln/detail/CVE-2021-35525
security-tracker.debian.org/tracker/CVE-2021-35525
www.cve.org/CVERecord?id=CVE-2021-35525
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:N/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS
Percentile
53.1%