Quantcast
Channel: CERT Recently Published Vulnerability Notes
Viewing all articles
Browse latest Browse all 129

VU#390745: OpenSMTPD vulnerable to local privilege escalation and remote code execution

$
0
0
OpenSMTPD is an open-source server-side implementation of the Simple Mail Transfer Protocol(SMTP)that is part of the OpenBSD Project. OpenSMTPD's smtp_mailaddr()function is responsible for validating sender and recipient mail addresses. If the local part of an address is invalid and the domain name is empty,smtp_mailaddr()will automatically add a domain name as opposed to failing because of the invalid local address. This will allow the invalid local address to pass through the function without validation.

Viewing all articles
Browse latest Browse all 129

Trending Articles