SMTP: Sendmail Headers Prescan Denial Of Service

This signature detects attempts to exploit a known vulnerability against Sendmail versions 8.9.2 and earlier. Attackers can send multiple headers in a maliciously crafted SMTP HELO message to create a denial-of-service attack against the message transfer agent (MTA).

Extended Description

Sendmail has been reported prone to a denial of service vulnerability when handling malicious SMTP mail headers. The vulnerability has been reported to present itself, due to an inefficient implementation of a header prescan algorithm. A remote attacker may reportedly deny service to legitimate users by sending specially crafted emails to the affected service. *** November 20, 2003 - This BID was erroneously updated today regarding the release of IBM AIX APARs released to address the Sendmail vulnerability described in BID 8641. The appropriate updates and changes have been made.

Affected Products

Sendmail_consortium sendmail

References

BugTraq: 8674

CVE: CVE-1999-0393

Short Name
SMTP:DOS:SENDMAIL-HEADERS-DOS
Severity
Minor
Recommended
False
Recommended Action
None
Category
SMTP
Keywords
CVE-1999-0393 Denial Headers Of Prescan Sendmail Service bid:8674
Release Date
04/25/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Sendmail_consortium

Ibm

CVSS Score

5.0

Found a potential security threat?