Sendmail < 8.10.0 mail.local Newline Handling Remote DoS

This script is Copyright (C) 2003-2012 Xue Yong Zhi


Synopsis :

The remote host has an application that is affected by a
denial of service vulnerability.

Description :

mail.local in the remote sendmail server, according to its version
number, does not properly identify the .\n string which identifies the
end of message text, which allows a remote attacker to cause a denial
of service or corrupt mailboxes via a message line that is 2047
characters long and ends in .\n.

Solution :

Install sendmail version 8.10.0 and higher, or install a vendor
supplied patch.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS Temporal Score : 3.7
(CVSS2#E:U/RL:OF/RC:C)

Family: SMTP problems

Nessus Plugin ID: 11351 ()

Bugtraq ID: 1146

CVE ID: CVE-2000-0319