Sendmail Milter Remote Denial Of Service Weakness
BID:14047
Info
Sendmail Milter Remote Denial Of Service Weakness
| Bugtraq ID: | 14047 |
| Class: | Configuration Error |
| CVE: |
CVE-2005-2070 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 23 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Damian Menscher <[email protected]> reported this vulnerability. |
| Vulnerable: |
SuSE Linux Enterprise Server 9 Sendmail Consortium Sendmail 8.12.11 Sendmail Consortium Sendmail 8.12.10 Sendmail Consortium Sendmail 8.12.9 Sendmail Consortium Sendmail 8.12.8 Sendmail Consortium Sendmail 8.12.7 Sendmail Consortium Sendmail 8.12.6 Sendmail Consortium Sendmail 8.12.5 Sendmail Consortium Sendmail 8.12.4 Sendmail Consortium Sendmail 8.12.3 Sendmail Consortium Sendmail 8.12.2 Sendmail Consortium Sendmail 8.12.1 Sendmail Consortium Sendmail 8.12 beta7 Sendmail Consortium Sendmail 8.12 beta5 Sendmail Consortium Sendmail 8.12 beta16 Sendmail Consortium Sendmail 8.12 beta12 Sendmail Consortium Sendmail 8.12 beta10 Sendmail Consortium Sendmail 8.12 .0 Sendmail Consortium Sendmail 8.11.7 Sendmail Consortium Sendmail 8.11.6 Sendmail Consortium Sendmail 8.11.5 Sendmail Consortium Sendmail 8.11.4 Sendmail Consortium Sendmail 8.11.3 Sendmail Consortium Sendmail 8.11.2 Sendmail Consortium Sendmail 8.11.1 Sendmail Consortium Sendmail 8.11 Sendmail Consortium Sendmail 8.10.2 Sendmail Consortium Sendmail 8.10.1 Sendmail Consortium Sendmail 8.10 Sendmail Consortium Sendmail 8.9.3 Sendmail Consortium Sendmail 8.9.2 Sendmail Consortium Sendmail 8.9.1 Sendmail Consortium Sendmail 8.9 .0 Sendmail Consortium Sendmail 8.8.8 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: | |
Discussion
Sendmail Milter Remote Denial Of Service Weakness
Sendmail is susceptible to a remote denial of service weakness in its milter interface. This issue is due to overly long default timeouts configured for milters.
This issue is demonstrated with ClamAV versions prior to 0.86. Any other milter that utilizes similar operating methods as the older ClamAV milter will also expose this vulnerability in Sendmail.
Depending on the configuration of the milter interface, attackers may either exploit this issue to bypass milters, or to deny further email delivery on affected sites.
Sendmail is susceptible to a remote denial of service weakness in its milter interface. This issue is due to overly long default timeouts configured for milters.
This issue is demonstrated with ClamAV versions prior to 0.86. Any other milter that utilizes similar operating methods as the older ClamAV milter will also expose this vulnerability in Sendmail.
Depending on the configuration of the milter interface, attackers may either exploit this issue to bypass milters, or to deny further email delivery on affected sites.
Exploit / POC
Sendmail Milter Remote Denial Of Service Weakness
An exploit is not required.
An exploit is not required.
Solution / Fix
Sendmail Milter Remote Denial Of Service Weakness
Solution:
SuSE has released an advisory (SUSE-SA:2005:038) and fixes to address this issue. Please see the referenced advisory for further information.
Debian has released advisory DSA 737-1 to address various issues affecting clamav. Please see the referenced advisory for more information.
Conectiva Linux has released security announcement CLSA-2005:973 addressing this issue. Please see the referenced advisory for details on obtaining abd applying the appropriate updates.
Debian has released security advisory DSA 773-1 addressing several issues for their AMD64 port of the operating system. Please see the referenced advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
SuSE has released an advisory (SUSE-SA:2005:038) and fixes to address this issue. Please see the referenced advisory for further information.
Debian has released advisory DSA 737-1 to address various issues affecting clamav. Please see the referenced advisory for more information.
Conectiva Linux has released security announcement CLSA-2005:973 addressing this issue. Please see the referenced advisory for details on obtaining abd applying the appropriate updates.
Debian has released security advisory DSA 773-1 addressing several issues for their AMD64 port of the operating system. Please see the referenced advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Sendmail Milter Remote Denial Of Service Weakness
References:
References:
- Sendmail Homepage (Sendmail Consortium)
- long sendmail timeouts let attacker prevent milter quiesce (Damian Menscher
)