PT-2005-1050 · Debian · Bsmtpd

Bastian Blank

·

Published

2005-02-25

·

Updated

2008-09-05

·

CVE-2005-0107

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions bsmtpd versions 2.3 and earlier
Description The issue affects the bsmtpd package in Debian GNU/Linux, potentially leading to breaches in confidentiality, integrity, and availability of protected information. Exploitation can be carried out remotely. Specifically, bsmtpd does not properly sanitize e-mail addresses, allowing remote attackers to execute arbitrary commands.
Recommendations For versions 2.3 and earlier, update to a version later than 2.3 to resolve the issue. As a temporary workaround, consider restricting access to the bsmtpd service to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03712
CVE-2005-0107
DSA-690-1

Affected Products

Bsmtpd