Red Hat Sendmail Localhost.Localdomain Email Spoofing Vulnerability
BID:23742
Info
Red Hat Sendmail Localhost.Localdomain Email Spoofing Vulnerability
| Bugtraq ID: | 23742 |
| Class: | Configuration Error |
| CVE: |
CVE-2006-7176 |
| Remote: | Yes |
| Local: | No |
| Published: | May 01 2007 12:00AM |
| Updated: | May 03 2010 06:12PM |
| Credit: | Nathan I Olson is credited with the discovery of this vulnerability |
| Vulnerable: |
Redhat Sendmail 8.13.1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Avaya SES 2.0 Avaya Messaging Storage Server MM3.0 Avaya Message Networking MN 3.1 Avaya Message Networking Avaya IQ 5 Avaya Communication Manager 2.0.1 Avaya Communication Manager 2.0 Avaya Communication Manager 3.0 Avaya CCS 3.0 Avaya CCS 2.0 Avaya Aura SIP Enablement Services 3.0 |
| Not Vulnerable: | |
Discussion
Red Hat Sendmail Localhost.Localdomain Email Spoofing Vulnerability
Red Hat Sendmail is prone to a vulnerability that permits an attacker to send spoofed emails.
A successful exploit may allow an attacker to impersonate the localhost when sending an email message.
This issue affects Sendmail on Red Hat systems due to a configuration error. It is not currently known if this issue affects other releases of the software.
Red Hat Sendmail is prone to a vulnerability that permits an attacker to send spoofed emails.
A successful exploit may allow an attacker to impersonate the localhost when sending an email message.
This issue affects Sendmail on Red Hat systems due to a configuration error. It is not currently known if this issue affects other releases of the software.
Exploit / POC
Red Hat Sendmail Localhost.Localdomain Email Spoofing Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Red Hat Sendmail Localhost.Localdomain Email Spoofing Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Red Hat Sendmail Localhost.Localdomain Email Spoofing Vulnerability
References:
References:
- CVE-2006-7176 sendmail allows external mail with from address [email protected] (Red Hat)
- Sendmail Homepage (Sendmail Consortium)
- ASA-2007-248 sendmail security and bug fix update (RHSA-2007-0252) (Avaya)
- ASA-2010-114 sendmail security and bug fix update (RHSA-2010-0237) (Avaya)
- Red Hat Security Advisory RSA-2007:0252-2:sendmail security and bug fix update (Red Hat )