Sendmail Crafted ETRN Commands Remote DoS

This script is Copyright (C) 2003-2014 Xue Yong Zhi


Synopsis :

The remote host has an application that is affected by a
denial of service vulnerability.

Description :

The remote sendmail server, according to its version number,
allows remote attackers to cause a denial of service by
sending a series of ETRN commands then disconnecting from
the server, while Sendmail continues to process the commands
after the connection has been terminated.

Solution :

Install sendmail version 8.10.1 and higher, or install a
vendor-supplied patch.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS Temporal Score : 4.0
(CVSS2#E:U/RL:W/RC:ND)
Public Exploit Available : false

Family: SMTP problems

Nessus Plugin ID: 11350 ()

Bugtraq ID: 904

CVE ID: CVE-1999-1109