CVE-1999-0250: Critical severity Dan Bernstein Qmail vulnerability
Denial of service in Qmail through long SMTP commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
If supported, configure Qmail or place a front-end SMTP proxy to enforce a maximum SMTP command length and reject/close connections that send commands longer than the configured limit to mitigate the long-command DoS.
Qmail or front-end SMTP proxy maximum SMTP command length = enforce a reasonable maximum and reject commands that exceed it - Compensating control
Implement network-level mitigations until an official fix is available: use a firewall, SMTP proxy, WAF or rate-limiter to detect and drop or throttle connections that send excessively long SMTP commands, and restrict SMTP access to trusted sources where practical.
- Operational
Monitor vendor advisories for an official patch addressing the denial-of-service via long SMTP commands and apply the vendor update as soon as it is released; in the interim, review mail server logs for signs of attempted exploitation and retain evidence for incident response.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0250?
CVE-1999-0250 is classified as a denial of service vulnerability.
How do I fix CVE-1999-0250?
To fix CVE-1999-0250, upgrade to a version of Qmail later than 1.01 that has patched this vulnerability.
What software is affected by CVE-1999-0250?
CVE-1999-0250 affects Qmail versions up to and including 1.01.
What kind of attack does CVE-1999-0250 facilitate?
CVE-1999-0250 facilitates denial of service attacks through long SMTP commands.
When was CVE-1999-0250 discovered?
CVE-1999-0250 was reported in 1999.