I'm receiving smtp vulnerability messages when scanning a linux 2.4.18 system running Exim 3.35. I am running a scan with all plugins enabled. The 2 plugins in question are 10050(CSM mail server) and 10047 (CMail).
However, I did not see Exim vulnerable to buffer overflow when running the NASL plugins individually or using something like:

perl -e 'print "HELO "; print "a" x 12000; print "\n"' | nc localhost 25

Cheers

--
Robert Petkus
UNIX Services
Brookhaven National Laboratory
The Modular Building
[EMAIL PROTECTED]


Reply via email to