CVE-2003-1362: High severity HPE HP-UX vulnerability
Bastille B.02.00.00 of HP-UX 11.00 and 11.11 does not properly configure the (1) NOVRFY and (2) NOEXPN options in the sendmail.cf file, which could allow remote attackers to verify the existence of system users and expand defined sendmail aliases.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Edit the sendmail.cf file and enable/set the NOVRFY and NOEXPN options so that sendmail does not allow remote VRFY or EXPN queries (prevent user verification and alias expansion).
sendmail (sendmail.cf) on HP Bastille B.02.00.00 / HP-UX 11.00 and 11.11 NOVRFY, NOEXPN = enabled
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1362?
CVE-2003-1362 has a moderate severity rating due to its potential to allow remote attackers to verify the existence of system users.
How do I fix CVE-2003-1362?
To remediate CVE-2003-1362, review and properly configure the NOVRFY and NOEXPN options in the sendmail.cf file.
What versions of HP-UX are affected by CVE-2003-1362?
CVE-2003-1362 affects HP-UX versions 11.00 and 11.11 when using Bastille B.02.00.00.
Can CVE-2003-1362 lead to information disclosure?
Yes, CVE-2003-1362 can lead to information disclosure by allowing attackers to enumerate valid users on the system.
Is there a known exploit for CVE-2003-1362?
As of now, there are no public exploits specifically targeting CVE-2003-1362, but the vulnerability can still be exploited if not mitigated.