Spam Filter ISP Support Forum

  New Posts New Posts RSS Feed - CVE-1999-0203
  FAQ FAQ  Forum Search   Register Register  Login Login

CVE-1999-0203

 Post Reply Post Reply
Author
LOBrien View Drop Down
Guest Group
Guest Group
Post Options Post Options   Thanks (0) Thanks(0)   Quote LOBrien Quote  Post ReplyReply Direct Link To This Post Topic: CVE-1999-0203
    Posted: 27 May 2004 at 2:03pm
When scanning my "LogSat Spam" server for security vulnerabilities, I receive a vulnerability CVE-1999-0203 (ref link):

http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=1999-0203

How can I fix this and/or document that it is a false positive?
Back to Top
LogSat View Drop Down
Admin Group
Admin Group
Avatar

Joined: 25 January 2005
Location: United States
Status: Offline
Points: 4104
Post Options Post Options   Thanks (0) Thanks(0)   Quote LogSat Quote  Post ReplyReply Direct Link To This Post Posted: 27 May 2004 at 11:39pm

LoBrien,

As the Mitre link you sent explains, the vulnerability only affects certain versions of SendMail. SpamFilter ISP is not based on Sendmail and is thus immune to that attack.

Your vulnerability scanner misinterpreted the response SpamFilter provided when it sent SpamFilter a malformatted rcpt to command followed by a specific sequence of bytes. You may want to inform the vendor of the false positives you received so they can fine tune their detection signature for this vulnerability.

You'll find more detailed explanation that Mitre provides, along with some sample signatures and vulnerable Sendmail versions here (Snort.org) and here (Whitehats)

Roberto F.
LogSat Software

 

Back to Top
 Post Reply Post Reply
  Share Topic   

Forum Jump Forum Permissions View Drop Down



This page was generated in 0.160 seconds.