QID 330170
QID 330170: IBM AIX Sendmail Email Spoofing Vulnerability (sendmail_advisory4)
Vulnerability in sendmail could allow a remote attacker to spoof an email (CVE-2023-51765).
Affected Platforms:
AIX 7.2, 7.3
QID Detection Logic (Authenticated):
The detection checks for installed packages version via command : lslpp -L | grep -i bos.net.tcp.sendmail
It also checks for interim fixes installed using the command emgr -c or instfix -k.
The detection posts vulnerable if installed package version is less than patched version and interim fixes are also not installed.
An attacker allow a remote attacker to spoof an email
Solution
The vendor has released fixes to resolve this vulnerability. Refer to AIX Advisory to obtain more information
Vendor References
- sendmail_advisory4 -
aix.software.ibm.com/aix/efixes/security/sendmail_advisory4.asc
CVEs related to QID 330170
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| sendmail_advisory4 |
|