|
Sendmail contains a flaw that allows a remote attacker to bypass mail logging. The issue is due to a flaw in handling overly long IDENT requests. If a remote attacker supplies an IDENT argument longer than 95 characters, the daemon will not properly log the request or subsequent commands such as VRFY, EXPN, and ETRN.
|