Sendmail WIZ Default Configuration Vulnerability
BID:2897
Info
Sendmail WIZ Default Configuration Vulnerability
| Bugtraq ID: | 2897 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 03 1988 12:00AM |
| Updated: | Nov 03 1988 12:00AM |
| Credit: | The first known incident of this vulnerability being exploited was by the Morris Internet Worm in 1988. |
| Vulnerable: |
Sendmail Consortium Sendmail 5.59 Sendmail Consortium Sendmail 4.55 Sendmail Consortium Sendmail 4.1 |
| Not Vulnerable: | |
Solution / Fix
Sendmail WIZ Default Configuration Vulnerability
Solution:
Upgrade to newer, unaffected versions of Sendmail.
Or if you are running a vulnerable version you can disable the WIZ command by adding the string 'OW*' to 'sendmail.cf', which is the configuration file for the package.
Solution:
Upgrade to newer, unaffected versions of Sendmail.
Or if you are running a vulnerable version you can disable the WIZ command by adding the string 'OW*' to 'sendmail.cf', which is the configuration file for the package.
References
Sendmail WIZ Default Configuration Vulnerability
References:
References: