Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.153183
Kategorie:SMTP problems
Titel:OpenSMTPD < 6.6.2p1 RCE Vulnerability - Active Check
Zusammenfassung:OpenSMTPD is prone to a remote code execution (RCE); vulnerability.
Beschreibung:Summary:
OpenSMTPD is prone to a remote code execution (RCE)
vulnerability.

Vulnerability Insight:
smtp_mailaddr in smtp_session.c in OpenSMTPD allows remote
attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by
shell metacharacters in a MAIL FROM field. This affects the 'uncommented' default configuration.
The issue exists because of an incorrect return value upon failure of input validation.

Affected Software/OS:
OpenSMTPD version 6.6.x prior to 6.6.2p1.

Solution:
Update to version 6.6.2p1 or later.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2020-7247
Bugtraq: 20200129 [SECURITY] [DSA 4611-1] opensmtpd security update (Google Search)
https://seclists.org/bugtraq/2020/Jan/51
CERT/CC vulnerability note: VU#390745
https://www.kb.cert.org/vuls/id/390745
Debian Security Information: DSA-4611 (Google Search)
https://www.debian.org/security/2020/dsa-4611
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OPH4QU4DNVHA7ACFXMYFCEP5PSXXPN4E/
http://seclists.org/fulldisclosure/2020/Jan/49
http://packetstormsecurity.com/files/156137/OpenBSD-OpenSMTPD-Privilege-Escalation-Code-Execution.html
http://packetstormsecurity.com/files/156145/OpenSMTPD-6.6.2-Remote-Code-Execution.html
http://packetstormsecurity.com/files/156249/OpenSMTPD-MAIL-FROM-Remote-Code-Execution.html
http://packetstormsecurity.com/files/156295/OpenSMTPD-6.6.1-Local-Privilege-Escalation.html
http://packetstormsecurity.com/files/162093/OpenBSD-OpenSMTPD-6.6-Remote-Code-Execution.html
http://www.openwall.com/lists/oss-security/2020/01/28/3
https://usn.ubuntu.com/4268-1/
CopyrightCopyright (C) 2024 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.