Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.53687
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-485)
Summary:The remote host is missing an update for the Debian 'ssmtp' package(s) announced via the DSA-485 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'ssmtp' package(s) announced via the DSA-485 advisory.

Vulnerability Insight:
Max Vozeler discovered two format string vulnerabilities in ssmtp, a simple mail transport agent. Untrusted values in the functions die() and log_event() were passed to printf-like functions as format strings. These vulnerabilities could potentially be exploited by a remote mail relay to gain the privileges of the ssmtp process (including potentially root).

For the current stable distribution (woody) this problem will be fixed in version 2.50.6.1.

For the unstable distribution (sid), this problem will be fixed soon.

We recommend that you update your ssmtp package.

Affected Software/OS:
'ssmtp' package(s) on Debian 3.0.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2004-0156
BugTraq ID: 10150
http://www.securityfocus.com/bid/10150
Bugtraq: 20040507 [OpenPKG-SA-2004.020] OpenPKG Security Advisory (ssmtp) (Google Search)
http://marc.info/?l=bugtraq&m=108403772130855&w=2
Debian Security Information: DSA-485 (Google Search)
http://www.debian.org/security/2004/dsa-485
http://security.gentoo.org/glsa/glsa-200404-18.xml
http://www.osvdb.org/5360
http://www.osvdb.org/5361
http://securitytracker.com/id?1009788
http://secunia.com/advisories/11378
http://secunia.com/advisories/11384
http://secunia.com/advisories/11485
http://secunia.com/advisories/11571
XForce ISS Database: ssmtp-die-logevent-format-string(15872)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15872
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.