Lucene search

K
cveMitreCVE-2003-1362
HistoryOct 17, 2007 - 1:00 a.m.

CVE-2003-1362

2007-10-1701:00:00
CWE-16
mitre
web.nvd.nist.gov
24
bastille
hp-ux
sendmail
configuration
vulnerability
cve-2003-1362

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

AI Score

7.1

Confidence

Low

EPSS

0.004

Percentile

74.2%

Bastille B.02.00.00 of HP-UX 11.00 and 11.11 does not properly configure the (1) NOVRFY and (2) NOEXPN options in the sendmail.cf file, which could allow remote attackers to verify the existence of system users and expand defined sendmail aliases.

Affected configurations

Nvd
Node
hpbastilleMatchb.02.00.05hp-ux
OR
hphp-uxMatch11.00
OR
hphp-uxMatch11.11
VendorProductVersionCPE
hpbastilleb.02.00.05cpe:2.3:a:hp:bastille:b.02.00.05:*:hp-ux:*:*:*:*:*
hphp-ux11.00cpe:2.3:o:hp:hp-ux:11.00:*:*:*:*:*:*:*
hphp-ux11.11cpe:2.3:o:hp:hp-ux:11.11:*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

AI Score

7.1

Confidence

Low

EPSS

0.004

Percentile

74.2%

Related for CVE-2003-1362