libs/comverp.c in Courier MTA before 0.53.2 allows attackers to cause a denial of service (CPU consumption) via unknown vectors involving usernames that contain the "=" (equals) character, which is not properly handled during encoding.
2006-05-30T19:02:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.8 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:C
10.0
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | double_precision_incorporated | courier_mta | ≤ 0.44.2 | Yes |
Application | double_precision_incorporated | courier_mta | 0.37.3 | Yes |
Application | double_precision_incorporated | courier_mta | 0.38.1 | Yes |
Application | double_precision_incorporated | courier_mta | 0.40 | Yes |
Application | double_precision_incorporated | courier_mta | 0.43 | Yes |
Application | double_precision_incorporated | courier_mta | 0.43.1 | Yes |
Application | double_precision_incorporated | courier_mta | 0.43.2 | Yes |
Application | double_precision_incorporated | courier_mta | 0.44 | Yes |