
DescriptionThe (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mails sent to an e-mail address, which allows remote attackers to send a large number of messages to arbitrary e-mail addresses (aka mail bomb).
Debian Bugs328224

The information below is based on the following data on fixed versions.

Direct flooding is possible as well in most circumstances.
(Upstream fix was in gforge

