CVE-2005-2431: Medium severity gforge gforge vulnerability
The (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mails sent to an e-mail address, which allows remote attackers to send a large number of messages to arbitrary e-mail addresses (aka mail bomb).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2431?
CVE-2005-2431 is considered a moderate severity vulnerability due to its ability to facilitate mail bombing.
How do I fix CVE-2005-2431?
To fix CVE-2005-2431, update GForge to a version beyond 4.5 where the mail sending limits have been implemented.
What impact does CVE-2005-2431 have on users?
CVE-2005-2431 allows attackers to send numerous unwanted emails to any specified address, potentially causing denial of service or overwhelming inboxes.
Are there any workarounds for CVE-2005-2431?
A temporary workaround for CVE-2005-2431 includes manually restricting the email functionalities or limiting email access by setting tighter controls.
Is CVE-2005-2431 still relevant today?
While CVE-2005-2431 has been addressed in later versions of GForge, its concept serves as a reminder of the importance of input validation and rate limiting.