Project

General

Profile

Actions

Security #6477

closed
PA PA

smtp: quadratic complexity from unbounded number of transaction per flow

Security #6477: smtp: quadratic complexity from unbounded number of transaction per flow

Added by Philippe Antoine over 2 years ago. Updated about 1 year ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Label:
Git IDs:

8f73a0ac5588cb5e5c501b3c7a07cb5d35b99d92

Severity:
CRITICAL
Disclosure Date:
01/24/2024


Subtasks 2 (0 open2 closed)

Security #6532: SMTP: quadratic complexity from unbounded number of transaction per flow (7.0.x backport)ClosedPhilippe AntoineActions
Security #6659: SMTP: quadratic complexity from unbounded number of transaction per flow (6.0.x backport)ClosedPhilippe AntoineActions

PA Updated by Philippe Antoine over 2 years ago Actions #1

  • Status changed from New to In Review

Gitlab

VJ Updated by Victor Julien over 2 years ago Actions #2

  • Target version changed from 7.0.3 to 8.0.0-beta1
  • Label Needs backport to 7.0 added

OT Updated by OISF Ticketbot over 2 years ago Actions #3

  • Subtask #6532 added

OT Updated by OISF Ticketbot over 2 years ago Actions #4

  • Label deleted (Needs backport to 7.0)

PA Updated by Philippe Antoine over 2 years ago Actions #5

  • Disclosure Date set to 01/24/2024

VJ Updated by Victor Julien over 2 years ago Actions #6

  • Severity changed from MODERATE to CRITICAL

CRITICAL as this can be used to slow down to the point of DoS.

VJ Updated by Victor Julien over 2 years ago Actions #7

  • Label Needs backport to 6.0 added

OT Updated by OISF Ticketbot over 2 years ago Actions #8

  • Subtask #6659 added

OT Updated by OISF Ticketbot over 2 years ago Actions #9

  • Label deleted (Needs backport to 6.0)

VJ Updated by Victor Julien about 2 years ago Actions #10

  • Status changed from In Review to Resolved
  • CVE set to 2024-23836

PA Updated by Philippe Antoine about 2 years ago Actions #11

  • Status changed from Resolved to Closed
  • Git IDs updated (diff)

VJ Updated by Victor Julien about 2 years ago Actions #12

  • Private changed from Yes to No

VJ Updated by Victor Julien about 1 year ago Actions #14

  • Subject changed from SMTP: quadratic complexity from unbounded number of transaction per flow to smtp: quadratic complexity from unbounded number of transaction per flow
Actions

Also available in: PDF Atom