VDB

CVE-2021-35525

CVE-2021-35525 PUBLISHED

PostSRSd before 1.11 allows a denial of service (subprocess hang) if Postfix sends certain long data fields such as multiple concatenated email addresses. NOTE: the PostSRSd maintainer acknowledges "theoretically, this error should never occur ... I'm not sure if there's a reliable way to trigger this condition by an external attacker, but it is a security bug in PostSRSd nevertheless."

EPSS 0.61% · 70.3th percentile

Risk Scores

EPSS Score
0.61%
70.3th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSpostsrsd0, 1.5-2
Ubuntu:24.04:LTSpostsrsd1.10-2.1build1, 1.10-2, 0
Ubuntu:22.04:LTSpostsrsd0, 1.10-2
Ubuntu:25.10postsrsd1.10-2.2, 0
Ubuntu:16.04:LTSpostsrsd0, 1.2-1
Ubuntu:18.04:LTSpostsrsd0, 1.4-1ubuntu0.1, 1.4-1

Timeline

  • Jun 28, 2021 CVE Published
  • Jun 29, 2021 EPSS Score
  • Aug 28, 2021 EPSS Score
  • Oct 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 25, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Apr 26, 2022 EPSS Score
  • Jun 25, 2022 EPSS Score
  • Oct 24, 2022 EPSS Score
  • Dec 24, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›