First published: Tue Mar 27 2007(Updated: )
The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not reject the "localhost.localdomain" domain name for e-mail messages that come from external hosts, which might allow remote attackers to spoof messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Linux | =4.0-update4 | |
Sendmail | =8.13.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-7176 is classified as a moderate severity vulnerability.
To fix CVE-2006-7176, upgrade Sendmail to a version that addresses this vulnerability.
CVE-2006-7176 affects Sendmail version 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier.
Yes, CVE-2006-7176 can allow remote attackers to spoof email messages from external hosts.
Yes, attackers can exploit CVE-2006-7176 to send spoofed emails if the vulnerable software is in use.