Sendmail check_relay Access Bypassing Vulnerability
BID:6548
Info
Sendmail check_relay Access Bypassing Vulnerability
| Bugtraq ID: | 6548 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-2261 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 03 2002 12:00AM |
| Updated: | Feb 05 2010 08:21PM |
| Credit: | This vulnerability was discovered by Kai Schlichting. |
| Vulnerable: |
Sendmail Consortium Sendmail 8.12.6 Sendmail Consortium Sendmail 8.12.5 Sendmail Consortium Sendmail 8.12.4 Sendmail Consortium Sendmail 8.12.3 Sendmail Consortium Sendmail 8.12.2 Sendmail Consortium Sendmail 8.12.1 Sendmail Consortium Sendmail 8.9.3 Sendmail Consortium Sendmail 8.9.2 Sendmail Consortium Sendmail 8.9.1 Sendmail Consortium Sendmail 8.9 .0 HP HP-UX B.11.23 HP HP-UX B.11.11 HP HP-UX B.11.11 Avaya Proactive Contact 3.0.3 Avaya Proactive Contact 3.0.2 Avaya Proactive Contact 3.0 Avaya Proactive Contact 0 |
| Not Vulnerable: |
Sendmail Consortium Sendmail 8.12.7 Sendmail Consortium Sendmail 8.9.3 Sendmail Consortium Sendmail 8.9.2 |
Discussion
Sendmail check_relay Access Bypassing Vulnerability
A vulnerability in Sendmail may allow attackers who use bogus DNS data to bypass the access restrictions imposed by the 'access_db' FEATURE when used with the 'check_relay' ruleset.
An attacker can exploit this vulnerability to connect to a sendmail server that would otherwise be inaccessible.
A vulnerability in Sendmail may allow attackers who use bogus DNS data to bypass the access restrictions imposed by the 'access_db' FEATURE when used with the 'check_relay' ruleset.
An attacker can exploit this vulnerability to connect to a sendmail server that would otherwise be inaccessible.
Exploit / POC
Sendmail check_relay Access Bypassing Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Sendmail check_relay Access Bypassing Vulnerability
Solution:
Updates are available. Please see the references for details.
HP HP-UX B.11.11
HP HP-UX B.11.23
Sendmail Consortium Sendmail 8.12.1
Sendmail Consortium Sendmail 8.12.2
Sendmail Consortium Sendmail 8.12.3
Sendmail Consortium Sendmail 8.12.4
Sendmail Consortium Sendmail 8.12.5
Sendmail Consortium Sendmail 8.12.6
Sendmail Consortium Sendmail 8.9 .0
Sendmail Consortium Sendmail 8.9.1
Solution:
Updates are available. Please see the references for details.
HP HP-UX B.11.11
-
HP PHNE_40393
http://itrc.hp.com
HP HP-UX B.11.23
-
HP PHNE_40388
http://itrc.hp.com
Sendmail Consortium Sendmail 8.12.1
-
Sendmail Consortium proto.m4.8.649.2.13
http://www.sendmail.org/patches/proto.m4.8.649.2.13 -
Sendmail Consortium sendmail.8.12.7.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.7.tar.gz
Sendmail Consortium Sendmail 8.12.2
-
Sendmail Consortium proto.m4.8.649.2.13
http://www.sendmail.org/patches/proto.m4.8.649.2.13 -
Sendmail Consortium sendmail.8.12.7.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.7.tar.gz
Sendmail Consortium Sendmail 8.12.3
-
Sendmail Consortium proto.m4.8.649.2.13
http://www.sendmail.org/patches/proto.m4.8.649.2.13 -
Sendmail Consortium sendmail.8.12.7.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.7.tar.gz
Sendmail Consortium Sendmail 8.12.4
-
Sendmail Consortium proto.m4.8.649.2.13
http://www.sendmail.org/patches/proto.m4.8.649.2.13 -
Sendmail Consortium sendmail.8.12.7.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.7.tar.gz
Sendmail Consortium Sendmail 8.12.5
-
Sendmail Consortium proto.m4.8.649.2.13
http://www.sendmail.org/patches/proto.m4.8.649.2.13 -
Sendmail Consortium sendmail.8.12.7.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.7.tar.gz
Sendmail Consortium Sendmail 8.12.6
-
Sendmail Consortium proto.m4.8.649.2.13
http://www.sendmail.org/patches/proto.m4.8.649.2.13 -
Sendmail Consortium sendmail.8.12.7.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.7.tar.gz
Sendmail Consortium Sendmail 8.9 .0
-
Sendmail Consortium proto.m4.8.9.3
http://www.sendmail.org/patches/proto.m4.8.9.3
Sendmail Consortium Sendmail 8.9.1
-
Sendmail Consortium proto.m4.8.9.3
http://www.sendmail.org/patches/proto.m4.8.9.3
References
Sendmail check_relay Access Bypassing Vulnerability
References:
References:
- Sendmail Homepage (Sendmail Consortium)
- ASA-2010-027 HPSBUX02495 SSRT090151 rev.2 - HP-UX Running sendmail, Remote Denia (Avaya)