CVE-2008-2784
Summary
| CVE | CVE-2008-2784 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-06-19 20:41:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The smtp_filter function in spamdyke before 3.1.8 does not filter RCPT commands after encountering the first DATA command, which allows remote attackers to use the server as an open mail relay by sending RCPT commands with invalid recipients, followed by a DATA command, followed by arbitrary RCPT commands and a second DATA command. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:N/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Spamdyke | Spamdyke | 3.0.0 | All | All | All |
| Application | Spamdyke | Spamdyke | 3.0.1 | All | All | All |
| Application | Spamdyke | Spamdyke | 3.1.0 | All | All | All |
| Application | Spamdyke | Spamdyke | 3.1.1 | All | All | All |
| Application | Spamdyke | Spamdyke | 3.1.2 | All | All | All |
| Application | Spamdyke | Spamdyke | 3.1.3 | All | All | All |
| Application | Spamdyke | Spamdyke | 3.1.4 | All | All | All |
| Application | Spamdyke | Spamdyke | 3.1.5 | All | All | All |
| Application | Spamdyke | Spamdyke | 3.1.6 | All | All | All |
| Application | Spamdyke | Spamdyke | 3.1.7 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.spamdyke.org/documentation/Changelog.txt | af854a3a-2127-422b-91ae-364da2661108 | www.spamdyke.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| spamdyke "smtp_filter()" DATA Command Relay Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.