Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:28836
HistoryDec 29, 2020 - 1:02 a.m.

Denial Of Service (DoS)

2020-12-2901:02:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
opensmtpd vulnerability
denial of service
remote attackers
null pointer dereference
daemon crash
malicious pattern
filter state machine
i/o channel

EPSS

0.008

Percentile

81.1%

opensmtpd is vulnerable to denial of service. The smtpd/lka_filter.c, in certain configurations, allows remote attackers to cause a denial of service via a NULL pointer dereference and daemon crash using a malicious pattern of client activity as the filter state machine does not properly maintain the I/O channel between the SMTP engine and the filters layer.