Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced
Published Aug 29, 2006
7.5
HIGHCVSS 3.1
EPSS 4.55%
Description
Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected."
Affected products
Remediation
Red Hat statement
This flaw causes a crash but does not result in a denial of service against Sendmail and is therefore not a security issue.
References (22)
- http://secunia.com/advisories/21637 third-party-advisoryx_refsource_SECUNIABroken LinkPatchVendor Advisory
- http://secunia.com/advisories/21641 third-party-advisoryx_refsource_SECUNIABroken LinkPatchVendor Advisory
- http://secunia.com/advisories/21696 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/21700 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/21749 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/22369 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://securitytracker.com/id?1016753 vdb-entryx_refsource_SECTRACKBroken LinkPatchThird Party AdvisoryVDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102664-1 vendor-advisoryx_refsource_SUNALERTBroken Link
- http://www.attrition.org/pipermail/vim/2006-August/000999.html mailing-listx_refsource_VIMMailing List
- http://www.debian.org/security/2006/dsa-1164 vendor-advisoryx_refsource_DEBIANBroken Link
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:156 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.novell.com/linux/security/advisories/2006_21_sr.html vendor-advisoryx_refsource_SUSEBroken Link
- http://www.openbsd.org/errata.html#sendmail3 vendor-advisoryx_refsource_OPENBSDRelease Notes
- http://www.openbsd.org/errata38.html#sendmail3 vendor-advisoryx_refsource_OPENBSDThird Party Advisory
- http://www.osvdb.org/28193 vdb-entryx_refsource_OSVDBBroken Link
- http://www.securityfocus.com/bid/19714 vdb-entryx_refsource_BIDBroken LinkPatchThird Party AdvisoryVDB Entry
- http://www.sendmail.org/releases/8.13.8.html x_refsource_CONFIRMRelease Notes
- http://www.vupen.com/english/advisories/2006/3393 vdb-entryx_refsource_VUPENBroken LinkVendor Advisory
- http://www.vupen.com/english/advisories/2006/3994 vdb-entryx_refsource_VUPENBroken LinkVendor Advisory
- https://access.redhat.com/security/cve/CVE-2006-4434 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2006-4434
- https://www.cve.org/CVERecord?id=CVE-2006-4434
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/21637 | third-party-advisoryx_refsource_SECUNIABroken LinkPatchVendor Advisory | |
| http://secunia.com/advisories/21641 | third-party-advisoryx_refsource_SECUNIABroken LinkPatchVendor Advisory | |
| http://secunia.com/advisories/21696 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/21700 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/21749 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/22369 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://securitytracker.com/id?1016753 | vdb-entryx_refsource_SECTRACKBroken LinkPatchThird Party AdvisoryVDB Entry | |
| http://sunsolve.sun.com/search/document.do?assetkey=1-26-102664-1 | vendor-advisoryx_refsource_SUNALERTBroken Link | |
| http://www.attrition.org/pipermail/vim/2006-August/000999.html | mailing-listx_refsource_VIMMailing List | |
| http://www.debian.org/security/2006/dsa-1164 | vendor-advisoryx_refsource_DEBIANBroken Link | |
| http://www.mandriva.com/security/advisories?name=MDKSA-2006:156 | vendor-advisoryx_refsource_MANDRIVABroken Link | |
| http://www.novell.com/linux/security/advisories/2006_21_sr.html | vendor-advisoryx_refsource_SUSEBroken Link | |
| http://www.openbsd.org/errata.html#sendmail3 | vendor-advisoryx_refsource_OPENBSDRelease Notes | |
| http://www.openbsd.org/errata38.html#sendmail3 | vendor-advisoryx_refsource_OPENBSDThird Party Advisory | |
| http://www.osvdb.org/28193 | vdb-entryx_refsource_OSVDBBroken Link | |
| http://www.securityfocus.com/bid/19714 | vdb-entryx_refsource_BIDBroken LinkPatchThird Party AdvisoryVDB Entry | |
| http://www.sendmail.org/releases/8.13.8.html | x_refsource_CONFIRMRelease Notes | |
| http://www.vupen.com/english/advisories/2006/3393 | vdb-entryx_refsource_VUPENBroken LinkVendor Advisory | |
| http://www.vupen.com/english/advisories/2006/3994 | vdb-entryx_refsource_VUPENBroken LinkVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2006-4434 | Vendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2006-4434 | ||
| https://www.cve.org/CVERecord?id=CVE-2006-4434 |
Change history (0)
No recorded changes yet.