Back

MEDIUM

sendmail: long first header can overflow into message body

Published May 5, 2009

Description

Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.

Affected products

Remediation

Red Hat statement

Based on our analysis this issue does not have a security consequence and does not lead to a buffer overflow or denial of service. For more details of our technical evaluation see https://bugzilla.redhat.com/show_bug.cgi?id=499252#c18

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 5, 2009
Updated Aug 7, 2024
Reserved Apr 30, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date Apr 30, 2009