SMTP: VRFY Command

This protocol anomaly triggers when it detects an attempt to use the SMTP VRFY command. This command is not used by most standard clients and servers and can reveal sensitive information about e-mail accounts.

Extended Description

A vulnerability exists in sendmail on all versions of SunOS up to version 4.0.3 which allows remote users user 'bin' access to the vulnerable host. This vulnerability is Sun bug # 1028173.

Affected Products

Sun sunos

Short Name
SMTP:COMMAND:VRFY
Severity
Minor
Recommended
False
Recommended Action
None
Category
SMTP
Keywords
CVE-1999-0531 bid:6
Release Date
08/27/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Sun

Found a potential security threat?