IBM AIX contains a flaw that may allow a malicious user to relay mail. The issue is triggered when AIX is installed with Sendmail configured as an open relay occurs. It is possible that the flaw may allow the server to be used for sending spam.
Classification
Location:
Remote / Network Access
Attack Type:
Misconfiguration
Impact:
Loss of Integrity
Exploit:
Exploit Public
Disclosure:
OSVDB Verified
Solution
Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround(s): reconfigure the Sendmail server to disable relaying and/or disable the Sendmail server. IBM has distributed updated sendmail.cf files with this issue fixed.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.