First published: Sun Apr 23 2000(Updated: )
mail.local in Sendmail 8.10.x does not properly identify the .\n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 2047 characters long and ends in .\n.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sendmail | =8.7.1 | |
Sendmail | =8.7.6 | |
Sendmail | =8.7.5 | |
Sendmail | =8.7.4 | |
Sendmail | =8.8.x | |
Sendmail | =8.8.2 | |
Sendmail | =8.9.1 | |
Sendmail | =8.8.1 | |
Sendmail | =8.7.2 | |
Sendmail | =8.9.3 | |
Sendmail | =8.6.x | |
Sendmail | =8.7.3 | |
Sendmail | =5.58 | |
Sendmail | =8.8.3 | |
Sendmail | =8.8.4 | |
Sendmail | =5.59 | |
Sendmail | =8.8 | |
Sendmail | =8.7.x | |
Sendmail | =8.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2000-0319 is considered moderate due to the possibility of denial of service or mailbox corruption.
To fix CVE-2000-0319, upgrade to a version of Sendmail that is not affected, such as 8.10.0 or later.
CVE-2000-0319 affects Sendmail versions 8.6.x to 8.9.x and some 8.7.x versions.
CVE-2000-0319 enables a remote attacker to cause a denial of service or corrupt mailboxes.
CVE-2000-0319 is a historical vulnerability, but systems still using old affected versions of Sendmail remain at risk.