Bugtraq mailing list archives
Re: Mail relay vulnerability in RedHat 5.0, 5.1, 5.2
From: roberto () EUROCONTROL FR (Ollivier Robert)
Date: Mon, 19 Jul 1999 18:33:17 +0200
According to David Luyer:
Users of sendmail 8.9.x of course have no problem, neither do those who have updated their mail relay prevention rulesets recently, but I think there are enough RedHat 5.0, 5.1 and 5.2 users who are unaware of the problem to make it worth sending this out.
Note that both Postfix and qmail are immune to this problem even though the smtpd daemon answer "250" to the RCPT TO command. Due ot the architecture of both programs, smtpd has no way to validate or not the "user" part of the address and the mail will bounce (i.e. il will NOT be relayed). Exim doesn't seem to be vulnerable (dixit P. Hazel in a discussion accross postfix and exim mailing-lists). -- Ollivier ROBERT -=- Eurocontrol EEC/TEC -=- roberto () eurocontrol fr The Postman hits! The Postman hits! You have new mail.
Current thread:
- Re: Shared memory DoS's (Redhat retraction), (continued)
- Re: Shared memory DoS's (Redhat retraction) Jim Dennis (Jul 19)
- Linux +ipchains+ ping -R Andrej Todosic (Jul 22)
- Re: Linux +ipchains+ ping -R Scott (Jul 23)
- Update to Microsoft Security Bulletin (MS99-025) aleph1 () UNDERGROUND ORG (Jul 23)
- Re: Shared memory DoS's (Redhat retraction) Wietse Venema (Jul 22)
- Alert: RDS IIS vulnerability/fix .rain.forest.puppy. (Jul 23)
- Re: Shared memory DoS's Dick St.Peters (Jul 15)
- Re: Shared memory DoS's Nicolas V. Chernyy (Jul 15)
- Re: Shared memory DoS's Mike Perry (Jul 17)
- Mail relay vulnerability in RedHat 5.0, 5.1, 5.2 David Luyer (Jul 16)
- Re: Mail relay vulnerability in RedHat 5.0, 5.1, 5.2 Ollivier Robert (Jul 19)
- Re: Mail relay vulnerability in RedHat 5.0, 5.1, 5.2 Matt Dunn (Jul 22)
- Re: Mail relay vulnerability in RedHat 5.0, 5.1, 5.2 Daniele Orlandi (Jul 24)
- Re: Shared memory DoS's Glynn Clements (Jul 16)
- Re: Shared memory DoS's Mike Perry (Jul 16)
- Re: Shared memory DoS's Howard Kaye (Jul 19)
- Samba 2.0.5 security fixes Andrew Tridgell (Jul 20)
- Re: Shared memory DoS's Richard Shetron (Jul 20)
- Delegate creates directories writable for anyone Olaf Seibert (Jul 21)
- Administrivia Aleph One (Jul 22)
- SNMP communities in 3Com HiPer Arcs (maybe other 3Com products?) Jeff Mcadams (Jul 20)
(Thread continues...)
