AIX Sendmail Open Relay Default Configuration Weakness
BID:7580
Info
AIX Sendmail Open Relay Default Configuration Weakness
| Bugtraq ID: | 7580 |
| Class: | Configuration Error |
| CVE: |
CVE-2003-0285 |
| Remote: | Yes |
| Local: | No |
| Published: | May 13 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery credited to Tom Perrine <[email protected]>. |
| Vulnerable: |
IBM AIX 5.1 L IBM AIX 4.3.3 IBM AIX 4.3.2 IBM AIX 4.3.1 IBM AIX 4.3 IBM AIX 5.2 IBM AIX 5.1 |
| Not Vulnerable: | |
Discussion
AIX Sendmail Open Relay Default Configuration Weakness
It has been reported that the default sendmail configuration on AIX systems enables promiscuous e-mail relaying options. Because of this, a remote attacker may be able to use the e-mail server to obscure the origins of e-mail.
It has been reported that the default sendmail configuration on AIX systems enables promiscuous e-mail relaying options. Because of this, a remote attacker may be able to use the e-mail server to obscure the origins of e-mail.
Exploit / POC
AIX Sendmail Open Relay Default Configuration Weakness
No exploit is required to take advantage of this weakness.
No exploit is required to take advantage of this weakness.
Solution / Fix
AIX Sendmail Open Relay Default Configuration Weakness
Solution:
The following fixes are available:
IBM AIX 5.1
IBM AIX 5.2
IBM AIX 4.3.3
Solution:
The following fixes are available:
IBM AIX 5.1
-
IBM sendmail_3_mod.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/sendmail_3_mod.tar.Z
IBM AIX 5.2
-
IBM sendmail_3_mod.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/sendmail_3_mod.tar.Z
IBM AIX 4.3.3
-
IBM sendmail_3_mod.tar.Z
ftp://aix.software.ibm.com/aix/efixes/security/sendmail_3_mod.tar.Z
References
AIX Sendmail Open Relay Default Configuration Weakness
References:
References:
- AIX sendmail open relay (Tom Perrine
)