CVE-2006-7176: Medium severity redhat Enterprise Linux vulnerability
Published Mar 27, 2007
·Updated
The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not reject the "localhost.localdomain" domain name for e-mail messages that come from external hosts, which might allow remote attackers to spoof messages.
Affected Software
2 affected components
redhat Enterprise Linux=4.0-update4
Sendmail Sendmail=8.13.1.2
Event History
Mar 27, 2007
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
11:19 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-7176?
CVE-2006-7176 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2006-7176?
To fix CVE-2006-7176, upgrade Sendmail to a version that addresses this vulnerability.
3
What systems are impacted by CVE-2006-7176?
CVE-2006-7176 affects Sendmail version 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier.
4
Can CVE-2006-7176 allow email spoofing?
Yes, CVE-2006-7176 can allow remote attackers to spoof email messages from external hosts.
5
Is CVE-2006-7176 exploitable by attackers?
Yes, attackers can exploit CVE-2006-7176 to send spoofed emails if the vulnerable software is in use.