CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer
image Vulnerabilities: - DNS Map Vulnerability in Sendmail 8.12.x - image
Email Servers
Most powerful is he who has himself in his own power.
Lucius Annaeus Seneca (2 BC-65AD) Roman philospher.

- DNS Map Vulnerability in Sendmail 8.12.x -
Oxygen3 24h-365d, by Panda Software (http://www.pandasoftware.com)

Madrid, August 27, 2003 - A new vulnerability has been detected that affects
Sendmail 8.12.x prior to 8.12.9. By exploiting this flaw, an attacker cause
a Denial of service (DoS) and run remote arbitrary code on the affected
computer.

Sendmail is the most commonly used MTA (Mail Transfer Agent) in mail
servers. This new vulnerability can occur when DNS maps are used. This
function was first implemented in Sendmail version 8.12, so this flaw does
not affect previous versions.

In order to carry out an attack, a DNS server must send an specially-crafted
reply to an affected system. This could crash the service and an attacker
could take advantage of this situation to run arbitrary code. Although
Sendmail Consortium has no reports that the vulnerability has been exploited
in order to run code, it is advisable to immediately update affected
systems.

Sendmail Consortium recommends updating to version 8.12.9, launched on the
March 29. Another solution is to apply a patch. For more details on this
problem, visit http://www.sendmail.org/dnsmap1.html.

NOTE: The address above may not show up on your screen as a single line.
This would prevent you from using the link to access the web page. If this
happens, just use the 'cut' and 'paste' options to join the pieces of the
URL.

-------------------------------------------------

The 5 most frequently detected viruses by Panda ActiveScan, Panda Software's
free online antivirus: 1) Blaster; 2) Sobig.F; 3) Bugbear.B; 4) Klez.I; 5)
PSWBugbear.B.
Posted on Thursday, 28 August 2003 @ 05:30:00 UTC by phoenix22 (1130 reads)
[ Trackback ]
image

"Vulnerabilities: - DNS Map Vulnerability in Sendmail 8.12.x -" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· HotScripts
· W3 Consortium
· More about Email Servers
· News by phoenix22


Most read story about Email Servers:
Hacking SMTP Mail Gateways

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer