Sendmail < 8.12.1 RestrictQueueRun Option Multiple Argument Local DoS

This script is Copyright (C) 2002-2012 Tenable Network Security, Inc.


Synopsis :

The remote mail server is vulnerable to a denial of service.

Description :

The remote Sendmail server, according to its version number, might be
vulnerable to a queue destruction when a local user runs

sendmail -q -h1000

If your system does not allow users to process the queue (which is the
default), you are not vulnerable.

Note that this vulnerability is _local_ only.

Solution :

Upgrade to Sendmail 8.12.1 or later. As a workaround, do not allow users to
process the queue (RestrictQRun option).

Risk factor :

Low / CVSS Base Score : 3.3
(CVSS2#AV:L/AC:M/Au:N/C:N/I:P/A:P)
CVSS Temporal Score : 2.4
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: SMTP problems

Nessus Plugin ID: 11087 ()

Bugtraq ID: 3378

CVE ID: CVE-2001-0714