Back to Database
Status published
High
CVE-2002-2261
Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying...
Vulnerability Description
Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the 'check_relay' function by spoofing a blank DNS hostname.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2002-2261
Credits & Attribution
No credits recorded in the NVD database.
References
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6892
- http://www.sendmail.org/8.12.7.html
- http://www.vupen.com/english/advisories/2009/3539
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8512
- http://securitytracker.com/id?1005748
- ftp://patches.sgi.com/support/free/security/advisories/20030101-01-P
- http://www.securityfocus.com/bid/6548
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10775
- http://secunia.com/advisories/7826
More from sendmail
View All →CVE-2009-4565
sendmail before 8.14.4 does not properly handle a '\0' character...
High
7.5
CVE-2009-1490
Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers...
Medium
5
CVE-2007-2246
Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail...
High
7.8
CVE-2006-7176
The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux...
Medium
4.3
CVE-2006-7175
The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux...
High
7.5
Affected Vendor
sendmail
View all reports →Affected Software
sendmail
Vulnerable Versions:
8.9.0, 8.9.1, 8.9.2, 8.9.3, 8.10, 8.10.0, 8.10.1, 8.10.2, 8.11.0, 8.11.1, 8.11.2, 8.11.3, 8.11.4, 8.11.5, 8.11.6, 8.11.7, 8.12, 8.12.0, 8.12.1, 8.12.2, 8.12.3, 8.12.4, 8.12.5, 8.12.6
Timeline
Official Publish:
October 18th, 2007
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.