CVE-2004-0833
published 2004-12-23CVE-2004-0833: Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configuration script with a fixed username and password, which could…
PriorityP428high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.51%
83.0th percentile
Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configuration script with a fixed username and password, which could allow remote attackers to use Sendmail as an open mail relay and send spam messages.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | sendmail | < sendmail 8.13.1-13 (bookworm) | sendmail 8.13.1-13 (bookworm) |
| sendmail | sendmail | >= 0 < 8.13.1-13 | 8.13.1-13 |
| sendmail | sendmail | >= 0 < 8.13.1-13 | 8.13.1-13 |
| sendmail | sendmail | >= 0 < 8.13.1-13 | 8.13.1-13 |
| sendmail | sendmail | >= 0 < 8.13.1-13 | 8.13.1-13 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9gjh-cfqr-c8q2: Sendmail before 8
ghsa_unreviewed·2022-04-29
CVE-2004-0833 [HIGH] GHSA-9gjh-cfqr-c8q2: Sendmail before 8
Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configuration script with a fixed username and password, which could allow remote attackers to use Sendmail as an open mail relay and send spam messages.
OSV
CVE-2004-0833: Sendmail before 8
osv·2004-12-23·CVSS 7.5
CVE-2004-0833 [HIGH] CVE-2004-0833: Sendmail before 8
Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configuration script with a fixed username and password, which could allow remote attackers to use Sendmail as an open mail relay and send spam messages.
Debian
CVE-2004-0833: sendmail - Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a...
vendor_debian·2004·CVSS 7.5
CVE-2004-0833 [HIGH] CVE-2004-0833: sendmail - Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a...
Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configuration script with a fixed username and password, which could allow remote attackers to use Sendmail as an open mail relay and send spam messages.
Scope: local
bookworm: resolved (fixed in 8.13.1-13)
bullseye: resolved (fixed in 8.13.1-13)
forky: resolved (fixed in 8.13.1-13)
sid: resolved (fixed in 8.13.1-13)
trixie: resolved (fixed in 8.13.1-13)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/12667http://www.debian.org/security/2004/dsa-554http://www.securityfocus.com/bid/11262https://exchange.xforce.ibmcloud.com/vulnerabilities/17531http://secunia.com/advisories/12667http://www.debian.org/security/2004/dsa-554http://www.securityfocus.com/bid/11262https://exchange.xforce.ibmcloud.com/vulnerabilities/17531
2004-12-23
Published