LWN.net Logo

sendmail: pre-set password

Package(s):sendmail CVE #(s):CAN-2004-0833
Created:September 27, 2004 Updated:September 29, 2004
Description: Hugo Espuny discovered a problem in sendmail, a commonly used program to deliver electronic mail. When installing "sasl-bin" to use sasl in connection with sendmail, the sendmail configuration script use fixed user/pass information to initialize the sasl database. Any spammer with Debian systems knowledge could utilize such a sendmail installation to relay spam.
Alerts:
Debian DSA-554-1 2004-09-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds