Executive Summary
Summary | |
---|---|
Title | New cgiemail packages fix open mail relaying |
Informations | |||
---|---|---|---|
Name | DSA-437 | First vendor Publication | 2004-02-11 |
Vendor | Debian | Last vendor Modification | 2004-02-11 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
A vulnerability was discovered in cgiemail, a CGI program used to email the contentsof an HTML form, whereby it could be used to send email to arbitrary addresses. This type of vulnerability is commonly exploited to send unsolicited commercial email (spam). For the current stable distribution (woody) this problem has been fixed in version 1.6-14woody1. For the unstable distribution (sid), this problem has been fixed in version 1.6-20. We recommend that you update your cgiemail package. |
Original Source
Url : http://www.debian.org/security/2004/dsa-437 |
CAPEC : Common Attack Pattern Enumeration & Classification
Id | Name |
---|---|
CAPEC-64 | Using Slashes and URL Encoding Combined to Bypass Validation Logic |
CAPEC-72 | URL Encoding |
CWE : Common Weakness Enumeration
% | Id | Name |
---|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2008-01-17 | Name : Debian Security Advisory DSA 437-1 (cgiemail) File : nvt/deb_437_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
3955 | cgiemail Open E-Mail Relay MIT cgiemail contains a flaw that allows a remote attacker to send e-mail without authentication. The issue us due to the program not asking or requiring authentication credentials to send e-mail. If an attacker (or spammer) uses this, mail can be sent through the server and made to appear from the victim network. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2004-09-29 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-437.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:33:04 |
|