First published: Tue Dec 31 2002(Updated: )
Sendmail 8.12.0 through 8.12.6 truncates log messages longer than 100 characters, which allows remote attackers to prevent the IP address from being logged via a long IDENT response.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sendmail | =8.12.3 | |
Sendmail | =8.12.4 | |
Sendmail | =8.12.1 | |
Sendmail | =8.12.5 | |
Sendmail | =8.12.0 | |
Sendmail | =8.12.6 | |
Sendmail | =8.12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2002-2423 is categorized as moderate, as it allows remote attackers to prevent IP address logging.
CVE-2002-2423 affects Sendmail versions 8.12.0 through 8.12.6.
To fix CVE-2002-2423, upgrade Sendmail to a version later than 8.12.6.
CVE-2002-2423 allows attackers to manipulate log entries by sending excessively long IDENT responses.
CVE-2002-2423 can cause important IP address logging information to be truncated or omitted.