The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not reject the localhost.localdomain domain name for e-mail messages that come from external hosts, which might allow remote attackers to spoof messages.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Enterprise_linux | Redhat | 4.0-update4 (including) | 4.0-update4 (including) |
Red Hat Enterprise Linux 4 | RedHat | sendmail-0:8.13.1-3.2.el4 | * |
Red Hat Enterprise Linux 5 | RedHat | sendmail-0:8.13.8-8.el5 | * |