PT-2004-1005 · Debian · Ssmtp

Published

2004-04-17

·

Updated

2017-07-11

·

CVE-2004-0156

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions ssmtp versions prior to 2.50.6
Description The issue concerns multiple vulnerabilities in the ssmtp package of the Debian GNU/Linux operating system. These vulnerabilities can be exploited remotely, potentially leading to a denial of service and possibly the execution of arbitrary code, thus compromising the availability of protected information.
Recommendations For versions prior to 2.50.6, update to version 2.50.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the die and log event functions to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-01364
CVE-2004-0156
DSA-485

Affected Products

Ssmtp