First published: Wed May 14 2003(Updated: )
IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam e-mail.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM AIX | <=5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0285 is considered a high severity vulnerability due to its potential for exploitation as an open mail relay.
To fix CVE-2003-0285, disable the promiscuous_relay, accept_unresolvable_domains, and accept_unqualified_senders settings in the Sendmail configuration.
CVE-2003-0285 affects IBM AIX versions 5.2 and earlier.
The impact of CVE-2003-0285 is that it allows unauthorized use of the Sendmail service for sending spam, leading to potential blacklisting of the server.
While CVE-2003-0285 may not be a current threat due to improvements in later versions, systems running affected versions remain at risk if not updated.