CVE-2002-1278
The mailconf module in Linuxconf 1.24, and other versions before 1.28, on Conectiva Linux 6.0 through 8, and possibly other distributions, generates the Sendmail configuration file (sendmail.cf) in a way that configures Sendmail to run as an open mail…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.45%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The mailconf module in Linuxconf 1.24, and other versions before 1.28, on Conectiva Linux 6.0 through 8, and possibly other distributions, generates the Sendmail configuration file (sendmail.cf) in a way that configures Sendmail to run as an open mail relay, which allows remote attackers to send Spam email.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.45% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- jacques gelinas/linuxconf
- Source
- cve@mitre.org
References
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000544
- http://www.iss.net/security_center/static/10554.phpVendor Advisory
- http://www.osvdb.org/6066
- http://www.securityfocus.com/bid/6118
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000544
- http://www.iss.net/security_center/static/10554.phpVendor Advisory
- http://www.osvdb.org/6066
- http://www.securityfocus.com/bid/6118
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.