Sendmail队列处理数据丢失/DoS漏洞

漏洞信息详情

Sendmail队列处理数据丢失/DoS漏洞

漏洞简介

无RestrictQueueRun选项可用的Sendmail 8.12.1之前版本存在漏洞。本地用户可以通过(1)设置高级首字母大写消息跳次计数选项(-h),可以导致Sendmail降低队列记录,(2)借助-qR选项,或(3)-qS选项导致服务拒绝(数据丢失)。

漏洞公告

Vendor fixes are available:
Sendmail Consortium Sendmail 8.10

Sendmail Consortium Sendmail 8.10.1

Sendmail Consortium Sendmail 8.10.2

Sendmail Consortium Sendmail 8.11

Sendmail Consortium Sendmail 8.11.1

Sendmail Consortium Sendmail 8.11.2

Sendmail Consortium Sendmail 8.11.3

Sendmail Consortium Sendmail 8.11.4

Sendmail Consortium Sendmail 8.11.5

Sendmail Consortium Sendmail 8.12 beta10

Sendmail Consortium Sendmail 8.12 beta5

Sendmail Consortium Sendmail 8.12 .0

Sendmail Consortium Sendmail 8.12 beta16

Sendmail Consortium Sendmail 8.12 beta7

Sendmail Consortium Sendmail 8.12 beta12

Sendmail Consortium Sendmail 8.9.3

参考网址

来源: BINDVIEW
名称: 20011001 Multiple Local Sendmail Vulnerabilities
链接:http://razor.bindview.com/publish/advisories/adv_sm812.html

来源: SGI
名称: 20011101-01-I
链接:ftp://patches.sgi.com/support/free/security/advisories/20011101-01-I

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享