Search

Find a vulnerability

Search criteria

    69 vulnerabilities by sendmail

    CVE-2023-51765 (GCVE-0-2023-51765)

    Vulnerability from nvd – Published: 2023-12-24 00:00 – Updated: 2024-08-02 22:48
    VLAI
    Summary
    sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports <LF>.<CR><LF> but some other popular e-mail servers do not. This is resolved in 8.18 and later versions with 'o' in srv_features.
    Severity
    No CVSS data available.
    CWE
    • n/a
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T22:48:11.197Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.openwall.com/lists/oss-security/2023/12/22/7"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.openwall.com/lists/oss-security/2023/12/21/7"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/freebsd/freebsd-src/commit/5dd76dd0cc19450133aa379ce0ce4a68ae07fb39#diff-afdf514b32ac88004952c11660c57bc96c3d8b2234007c1cbd8d7ed7fd7935cc"
              },
              {
                "name": "[oss-security] 20231224 Re: Re: New SMTP smuggling attack",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2023/12/24/1"
              },
              {
                "name": "[oss-security] 20231225 Re: Re: New SMTP smuggling attack",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2023/12/25/1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://bugzilla.suse.com/show_bug.cgi?id=1218351"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2255869"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/security/cve/CVE-2023-51765"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11782.html"
              },
              {
                "name": "[oss-security] 20231226 Re: New SMTP smuggling attack",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2023/12/26/5"
              },
              {
                "name": "[oss-security] 20231229 Re: Re: New SMTP smuggling attack",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2023/12/29/5"
              },
              {
                "name": "[oss-security] 20231230 Re: Re: New SMTP smuggling attack",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2023/12/30/3"
              },
              {
                "name": "[oss-security] 20231230 Re: Re: New SMTP smuggling attack",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2023/12/30/1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.youtube.com/watch?v=V8KPV96g1To"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lwn.net/Articles/956533/"
              },
              {
                "name": "[debian-lts-announce] 20240615 [SECURITY] [DLA 3829-1] sendmail security update",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00004.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports \u003cLF\u003e.\u003cCR\u003e\u003cLF\u003e but some other popular e-mail servers do not. This is resolved in 8.18 and later versions with \u0027o\u0027 in srv_features."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-15T09:05:58.617Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/"
            },
            {
              "url": "https://www.openwall.com/lists/oss-security/2023/12/22/7"
            },
            {
              "url": "https://www.openwall.com/lists/oss-security/2023/12/21/7"
            },
            {
              "url": "https://github.com/freebsd/freebsd-src/commit/5dd76dd0cc19450133aa379ce0ce4a68ae07fb39#diff-afdf514b32ac88004952c11660c57bc96c3d8b2234007c1cbd8d7ed7fd7935cc"
            },
            {
              "name": "[oss-security] 20231224 Re: Re: New SMTP smuggling attack",
              "tags": [
                "mailing-list"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2023/12/24/1"
            },
            {
              "name": "[oss-security] 20231225 Re: Re: New SMTP smuggling attack",
              "tags": [
                "mailing-list"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2023/12/25/1"
            },
            {
              "url": "https://bugzilla.suse.com/show_bug.cgi?id=1218351"
            },
            {
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2255869"
            },
            {
              "url": "https://access.redhat.com/security/cve/CVE-2023-51765"
            },
            {
              "url": "https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11782.html"
            },
            {
              "name": "[oss-security] 20231226 Re: New SMTP smuggling attack",
              "tags": [
                "mailing-list"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2023/12/26/5"
            },
            {
              "name": "[oss-security] 20231229 Re: Re: New SMTP smuggling attack",
              "tags": [
                "mailing-list"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2023/12/29/5"
            },
            {
              "name": "[oss-security] 20231230 Re: Re: New SMTP smuggling attack",
              "tags": [
                "mailing-list"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2023/12/30/3"
            },
            {
              "name": "[oss-security] 20231230 Re: Re: New SMTP smuggling attack",
              "tags": [
                "mailing-list"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2023/12/30/1"
            },
            {
              "url": "https://www.youtube.com/watch?v=V8KPV96g1To"
            },
            {
              "url": "https://lwn.net/Articles/956533/"
            },
            {
              "name": "[debian-lts-announce] 20240615 [SECURITY] [DLA 3829-1] sendmail security update",
              "tags": [
                "mailing-list"
              ],
              "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00004.html"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2023-51765",
        "datePublished": "2023-12-24T00:00:00.000Z",
        "dateReserved": "2023-12-24T00:00:00.000Z",
        "dateUpdated": "2024-08-02T22:48:11.197Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-3618 (GCVE-0-2021-3618)

    Vulnerability from nvd – Published: 2022-03-23 00:00 – Updated: 2024-08-03 17:01
    VLAI
    Summary
    ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
    Severity
    No CVSS data available.
    CWE
    Impacted products
    Vendor Product Version
    n/a ALPACA Affected: vsftpd 3.0.4, nginx 1.21.0, sendmail 8.17
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T17:01:07.459Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1975623"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://alpaca-attack.com/"
              },
              {
                "name": "[debian-lts-announce] 20221122 [SECURITY] [DLA 3203-1] nginx security update",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00031.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "ALPACA",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "vsftpd 3.0.4, nginx 1.21.0, sendmail 8.17"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim\u0027s traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-295",
                  "description": "CWE-295",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-11-23T00:00:00.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1975623"
            },
            {
              "url": "https://alpaca-attack.com/"
            },
            {
              "name": "[debian-lts-announce] 20221122 [SECURITY] [DLA 3203-1] nginx security update",
              "tags": [
                "mailing-list"
              ],
              "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00031.html"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2021-3618",
        "datePublished": "2022-03-23T00:00:00.000Z",
        "dateReserved": "2021-06-24T00:00:00.000Z",
        "dateUpdated": "2024-08-03T17:01:07.459Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2014-3956 (GCVE-0-2014-3956)

    Vulnerability from nvd – Published: 2014-06-04 10:00 – Updated: 2024-08-06 10:57
    VLAI
    Summary
    The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Date Public
    2014-05-21 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T10:57:18.265Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05216368"
              },
              {
                "name": "58628",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/58628"
              },
              {
                "name": "FreeBSD-SA-14:11",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FREEBSD",
                  "x_transferred"
                ],
                "url": "http://www.freebsd.org/security/advisories/FreeBSD-SA-14%3A11.sendmail.asc"
              },
              {
                "name": "MDVSA-2015:128",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2015:128"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://packetstormsecurity.com/files/126975/Slackware-Security-Advisory-sendmail-Updates.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "ftp://ftp.sendmail.org/pub/sendmail/RELEASE_NOTES"
              },
              {
                "name": "GLSA-201412-32",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://security.gentoo.org/glsa/glsa-201412-32.xml"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.sendmail.com/sm/open_source/download/8.14.9/"
              },
              {
                "name": "openSUSE-SU-2014:0804",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-updates/2014-06/msg00032.html"
              },
              {
                "name": "MDVSA-2014:147",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2014:147"
              },
              {
                "name": "FEDORA-2014-7093",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134349.html"
              },
              {
                "name": "openSUSE-SU-2014:0805",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-updates/2014-06/msg00033.html"
              },
              {
                "name": "57455",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/57455"
              },
              {
                "name": "67791",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/67791"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://advisories.mageia.org/MGASA-2014-0270.html"
              },
              {
                "name": "SSA:2014-156-04",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SLACKWARE",
                  "x_transferred"
                ],
                "url": "http://www.slackware.com/security/viewer.php?l=slackware-security\u0026y=2014\u0026m=slackware-security.728644"
              },
              {
                "name": "1030331",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id/1030331"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2014-05-21T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-12-28T19:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05216368"
            },
            {
              "name": "58628",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/58628"
            },
            {
              "name": "FreeBSD-SA-14:11",
              "tags": [
                "vendor-advisory",
                "x_refsource_FREEBSD"
              ],
              "url": "http://www.freebsd.org/security/advisories/FreeBSD-SA-14%3A11.sendmail.asc"
            },
            {
              "name": "MDVSA-2015:128",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2015:128"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://packetstormsecurity.com/files/126975/Slackware-Security-Advisory-sendmail-Updates.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "ftp://ftp.sendmail.org/pub/sendmail/RELEASE_NOTES"
            },
            {
              "name": "GLSA-201412-32",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://security.gentoo.org/glsa/glsa-201412-32.xml"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.sendmail.com/sm/open_source/download/8.14.9/"
            },
            {
              "name": "openSUSE-SU-2014:0804",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-updates/2014-06/msg00032.html"
            },
            {
              "name": "MDVSA-2014:147",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2014:147"
            },
            {
              "name": "FEDORA-2014-7093",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134349.html"
            },
            {
              "name": "openSUSE-SU-2014:0805",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-updates/2014-06/msg00033.html"
            },
            {
              "name": "57455",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/57455"
            },
            {
              "name": "67791",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/67791"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://advisories.mageia.org/MGASA-2014-0270.html"
            },
            {
              "name": "SSA:2014-156-04",
              "tags": [
                "vendor-advisory",
                "x_refsource_SLACKWARE"
              ],
              "url": "http://www.slackware.com/security/viewer.php?l=slackware-security\u0026y=2014\u0026m=slackware-security.728644"
            },
            {
              "name": "1030331",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id/1030331"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2014-3956",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05216368",
                  "refsource": "CONFIRM",
                  "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05216368"
                },
                {
                  "name": "58628",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/58628"
                },
                {
                  "name": "FreeBSD-SA-14:11",
                  "refsource": "FREEBSD",
                  "url": "http://www.freebsd.org/security/advisories/FreeBSD-SA-14%3A11.sendmail.asc"
                },
                {
                  "name": "MDVSA-2015:128",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2015:128"
                },
                {
                  "name": "http://packetstormsecurity.com/files/126975/Slackware-Security-Advisory-sendmail-Updates.html",
                  "refsource": "MISC",
                  "url": "http://packetstormsecurity.com/files/126975/Slackware-Security-Advisory-sendmail-Updates.html"
                },
                {
                  "name": "ftp://ftp.sendmail.org/pub/sendmail/RELEASE_NOTES",
                  "refsource": "CONFIRM",
                  "url": "ftp://ftp.sendmail.org/pub/sendmail/RELEASE_NOTES"
                },
                {
                  "name": "GLSA-201412-32",
                  "refsource": "GENTOO",
                  "url": "http://security.gentoo.org/glsa/glsa-201412-32.xml"
                },
                {
                  "name": "http://www.sendmail.com/sm/open_source/download/8.14.9/",
                  "refsource": "CONFIRM",
                  "url": "http://www.sendmail.com/sm/open_source/download/8.14.9/"
                },
                {
                  "name": "openSUSE-SU-2014:0804",
                  "refsource": "SUSE",
                  "url": "http://lists.opensuse.org/opensuse-updates/2014-06/msg00032.html"
                },
                {
                  "name": "MDVSA-2014:147",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2014:147"
                },
                {
                  "name": "FEDORA-2014-7093",
                  "refsource": "FEDORA",
                  "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134349.html"
                },
                {
                  "name": "openSUSE-SU-2014:0805",
                  "refsource": "SUSE",
                  "url": "http://lists.opensuse.org/opensuse-updates/2014-06/msg00033.html"
                },
                {
                  "name": "57455",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/57455"
                },
                {
                  "name": "67791",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/67791"
                },
                {
                  "name": "http://advisories.mageia.org/MGASA-2014-0270.html",
                  "refsource": "CONFIRM",
                  "url": "http://advisories.mageia.org/MGASA-2014-0270.html"
                },
                {
                  "name": "SSA:2014-156-04",
                  "refsource": "SLACKWARE",
                  "url": "http://www.slackware.com/security/viewer.php?l=slackware-security\u0026y=2014\u0026m=slackware-security.728644"
                },
                {
                  "name": "1030331",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id/1030331"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2014-3956",
        "datePublished": "2014-06-04T10:00:00.000Z",
        "dateReserved": "2014-06-03T00:00:00.000Z",
        "dateUpdated": "2024-08-06T10:57:18.265Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2009-4565 (GCVE-0-2009-4565)

    Vulnerability from nvd – Published: 2010-01-04 21:00 – Updated: 2024-08-07 07:08
    VLAI
    Summary
    sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://secunia.com/advisories/38314 third-party-advisoryx_refsource_SECUNIA
    http://security.gentoo.org/glsa/glsa-201206-30.xml vendor-advisoryx_refsource_GENTOO
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://secunia.com/advisories/39088 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2009/3661 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/37998 third-party-advisoryx_refsource_SECUNIA
    http://www.securityfocus.com/bid/37543 vdb-entryx_refsource_BID
    http://www.vupen.com/english/advisories/2011/0415 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/43366 third-party-advisoryx_refsource_SECUNIA
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://www.sendmail.org/releases/8.14.4 x_refsource_CONFIRM
    http://marc.info/?l=bugtraq&m=126953289726317&w=2 vendor-advisoryx_refsource_HP
    http://www.vupen.com/english/advisories/2010/0719 vdb-entryx_refsource_VUPEN
    http://www.redhat.com/support/errata/RHSA-2011-02… vendor-advisoryx_refsource_REDHAT
    http://www.debian.org/security/2010/dsa-1985 vendor-advisoryx_refsource_DEBIAN
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://secunia.com/advisories/40109 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/38915 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2010/1386 vdb-entryx_refsource_VUPEN
    Date Public
    2009-12-30 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T07:08:38.091Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "38314",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/38314"
              },
              {
                "name": "GLSA-201206-30",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://security.gentoo.org/glsa/glsa-201206-30.xml"
              },
              {
                "name": "1021797",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021797.1-1"
              },
              {
                "name": "39088",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/39088"
              },
              {
                "name": "ADV-2009-3661",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2009/3661"
              },
              {
                "name": "37998",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/37998"
              },
              {
                "name": "37543",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/37543"
              },
              {
                "name": "ADV-2011-0415",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2011/0415"
              },
              {
                "name": "43366",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/43366"
              },
              {
                "name": "SUSE-SR:2010:006",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html"
              },
              {
                "name": "oval:org.mitre.oval:def:10255",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10255"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.sendmail.org/releases/8.14.4"
              },
              {
                "name": "HPSBUX02508",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://marc.info/?l=bugtraq\u0026m=126953289726317\u0026w=2"
              },
              {
                "name": "ADV-2010-0719",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2010/0719"
              },
              {
                "name": "RHSA-2011:0262",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2011-0262.html"
              },
              {
                "name": "DSA-1985",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2010/dsa-1985"
              },
              {
                "name": "oval:org.mitre.oval:def:11822",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11822"
              },
              {
                "name": "SSRT100007",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://marc.info/?l=bugtraq\u0026m=126953289726317\u0026w=2"
              },
              {
                "name": "40109",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/40109"
              },
              {
                "name": "38915",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/38915"
              },
              {
                "name": "ADV-2010-1386",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2010/1386"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2009-12-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "sendmail before 8.14.4 does not properly handle a \u0027\\0\u0027 character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-09-18T12:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "38314",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/38314"
            },
            {
              "name": "GLSA-201206-30",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://security.gentoo.org/glsa/glsa-201206-30.xml"
            },
            {
              "name": "1021797",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021797.1-1"
            },
            {
              "name": "39088",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/39088"
            },
            {
              "name": "ADV-2009-3661",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2009/3661"
            },
            {
              "name": "37998",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/37998"
            },
            {
              "name": "37543",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/37543"
            },
            {
              "name": "ADV-2011-0415",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2011/0415"
            },
            {
              "name": "43366",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/43366"
            },
            {
              "name": "SUSE-SR:2010:006",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html"
            },
            {
              "name": "oval:org.mitre.oval:def:10255",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10255"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.sendmail.org/releases/8.14.4"
            },
            {
              "name": "HPSBUX02508",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://marc.info/?l=bugtraq\u0026m=126953289726317\u0026w=2"
            },
            {
              "name": "ADV-2010-0719",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2010/0719"
            },
            {
              "name": "RHSA-2011:0262",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2011-0262.html"
            },
            {
              "name": "DSA-1985",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2010/dsa-1985"
            },
            {
              "name": "oval:org.mitre.oval:def:11822",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11822"
            },
            {
              "name": "SSRT100007",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://marc.info/?l=bugtraq\u0026m=126953289726317\u0026w=2"
            },
            {
              "name": "40109",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/40109"
            },
            {
              "name": "38915",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/38915"
            },
            {
              "name": "ADV-2010-1386",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2010/1386"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2009-4565",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "sendmail before 8.14.4 does not properly handle a \u0027\\0\u0027 character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "38314",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/38314"
                },
                {
                  "name": "GLSA-201206-30",
                  "refsource": "GENTOO",
                  "url": "http://security.gentoo.org/glsa/glsa-201206-30.xml"
                },
                {
                  "name": "1021797",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021797.1-1"
                },
                {
                  "name": "39088",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/39088"
                },
                {
                  "name": "ADV-2009-3661",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2009/3661"
                },
                {
                  "name": "37998",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/37998"
                },
                {
                  "name": "37543",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/37543"
                },
                {
                  "name": "ADV-2011-0415",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2011/0415"
                },
                {
                  "name": "43366",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/43366"
                },
                {
                  "name": "SUSE-SR:2010:006",
                  "refsource": "SUSE",
                  "url": "http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html"
                },
                {
                  "name": "oval:org.mitre.oval:def:10255",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10255"
                },
                {
                  "name": "http://www.sendmail.org/releases/8.14.4",
                  "refsource": "CONFIRM",
                  "url": "http://www.sendmail.org/releases/8.14.4"
                },
                {
                  "name": "HPSBUX02508",
                  "refsource": "HP",
                  "url": "http://marc.info/?l=bugtraq\u0026m=126953289726317\u0026w=2"
                },
                {
                  "name": "ADV-2010-0719",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2010/0719"
                },
                {
                  "name": "RHSA-2011:0262",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2011-0262.html"
                },
                {
                  "name": "DSA-1985",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2010/dsa-1985"
                },
                {
                  "name": "oval:org.mitre.oval:def:11822",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11822"
                },
                {
                  "name": "SSRT100007",
                  "refsource": "HP",
                  "url": "http://marc.info/?l=bugtraq\u0026m=126953289726317\u0026w=2"
                },
                {
                  "name": "40109",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/40109"
                },
                {
                  "name": "38915",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/38915"
                },
                {
                  "name": "ADV-2010-1386",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2010/1386"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2009-4565",
        "datePublished": "2010-01-04T21:00:00.000Z",
        "dateReserved": "2010-01-04T00:00:00.000Z",
        "dateUpdated": "2024-08-07T07:08:38.091Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2009-1490 (GCVE-0-2009-1490)

    Vulnerability from nvd – Published: 2009-05-05 19:00 – Updated: 2024-08-07 05:13
    VLAI
    Summary
    Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Date Public
    2009-04-27 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T05:13:25.560Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.sendmail.org/releases/8.13.2"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://www.nmrc.org/~thegnome/blog/apr09/"
              },
              {
                "name": "sendmail-xheader-bo(50355)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/50355"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2009-04-27T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-08-16T14:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.sendmail.org/releases/8.13.2"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://www.nmrc.org/~thegnome/blog/apr09/"
            },
            {
              "name": "sendmail-xheader-bo(50355)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/50355"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2009-1490",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "http://www.sendmail.org/releases/8.13.2",
                  "refsource": "CONFIRM",
                  "url": "http://www.sendmail.org/releases/8.13.2"
                },
                {
                  "name": "http://www.nmrc.org/~thegnome/blog/apr09/",
                  "refsource": "MISC",
                  "url": "http://www.nmrc.org/~thegnome/blog/apr09/"
                },
                {
                  "name": "sendmail-xheader-bo(50355)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/50355"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2009-1490",
        "datePublished": "2009-05-05T19:00:00.000Z",
        "dateReserved": "2009-04-30T00:00:00.000Z",
        "dateUpdated": "2024-08-07T05:13:25.560Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2007-2246 (GCVE-0-2007-2246)

    Vulnerability from nvd – Published: 2007-04-25 16:00 – Updated: 2024-08-07 13:33
    VLAI
    Summary
    Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.1; allows remote attackers to cause a denial of service via unknown attack vectors. NOTE: due to the lack of details from HP, it is not known whether this issue is a duplicate of another CVE such as CVE-2006-1173 or CVE-2006-4434.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.securitytracker.com/id?1017966 vdb-entryx_refsource_SECTRACK
    http://www.securityfocus.com/bid/23606 vdb-entryx_refsource_BID
    http://www.kb.cert.org/vuls/id/349305 third-party-advisoryx_refsource_CERT-VN
    http://secunia.com/advisories/24990 third-party-advisoryx_refsource_SECUNIA
    http://h20000.www2.hp.com/bizsupport/TechSupport/… vendor-advisoryx_refsource_HP
    http://www.vupen.com/english/advisories/2007/1504 vdb-entryx_refsource_VUPEN
    Date Public
    2007-04-16 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T13:33:28.308Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "1017966",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1017966"
              },
              {
                "name": "23606",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/23606"
              },
              {
                "name": "VU#349305",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_CERT-VN",
                  "x_transferred"
                ],
                "url": "http://www.kb.cert.org/vuls/id/349305"
              },
              {
                "name": "24990",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/24990"
              },
              {
                "name": "SSRT061243",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00841370"
              },
              {
                "name": "HPSBUX02183",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00841370"
              },
              {
                "name": "ADV-2007-1504",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2007/1504"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2007-04-16T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.1; allows remote attackers to cause a denial of service via unknown attack vectors.  NOTE: due to the lack of details from HP, it is not known whether this issue is a duplicate of another CVE such as CVE-2006-1173 or CVE-2006-4434."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2007-05-02T09:00:00.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "1017966",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1017966"
            },
            {
              "name": "23606",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/23606"
            },
            {
              "name": "VU#349305",
              "tags": [
                "third-party-advisory",
                "x_refsource_CERT-VN"
              ],
              "url": "http://www.kb.cert.org/vuls/id/349305"
            },
            {
              "name": "24990",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/24990"
            },
            {
              "name": "SSRT061243",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00841370"
            },
            {
              "name": "HPSBUX02183",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00841370"
            },
            {
              "name": "ADV-2007-1504",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2007/1504"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2007-2246",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.1; allows remote attackers to cause a denial of service via unknown attack vectors.  NOTE: due to the lack of details from HP, it is not known whether this issue is a duplicate of another CVE such as CVE-2006-1173 or CVE-2006-4434."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "1017966",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id?1017966"
                },
                {
                  "name": "23606",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/23606"
                },
                {
                  "name": "VU#349305",
                  "refsource": "CERT-VN",
                  "url": "http://www.kb.cert.org/vuls/id/349305"
                },
                {
                  "name": "24990",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/24990"
                },
                {
                  "name": "SSRT061243",
                  "refsource": "HP",
                  "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00841370"
                },
                {
                  "name": "HPSBUX02183",
                  "refsource": "HP",
                  "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00841370"
                },
                {
                  "name": "ADV-2007-1504",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2007/1504"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2007-2246",
        "datePublished": "2007-04-25T16:00:00.000Z",
        "dateReserved": "2007-04-25T00:00:00.000Z",
        "dateUpdated": "2024-08-07T13:33:28.308Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2006-7175 (GCVE-0-2006-7175)

    Vulnerability from nvd – Published: 2007-03-27 23:00 – Updated: 2024-08-07 20:57
    VLAI
    Summary
    The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryption, which could cause less secure channels to be used than desired.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Date Public
    2006-08-18 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T20:57:39.637Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=172352"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2006-08-18T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryption, which could cause less secure channels to be used than desired."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-10-03T16:21:25.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=172352"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2006-7175",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryption, which could cause less secure channels to be used than desired."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=172352",
                  "refsource": "MISC",
                  "url": "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=172352"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2006-7175",
        "datePublished": "2007-03-27T23:00:00.000Z",
        "dateReserved": "2007-03-27T00:00:00.000Z",
        "dateUpdated": "2024-08-07T20:57:39.637Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2006-7176 (GCVE-0-2006-7176)

    Vulnerability from nvd – Published: 2007-03-27 23:00 – Updated: 2024-08-07 20:57
    VLAI
    Summary
    The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not reject the "localhost.localdomain" domain name for e-mail messages that come from external hosts, which might allow remote attackers to spoof messages.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://secunia.com/advisories/25098 third-party-advisoryx_refsource_SECUNIA
    https://bugzilla.redhat.com/bugzilla/show_bug.cgi… x_refsource_MISC
    http://www.redhat.com/support/errata/RHSA-2007-02… vendor-advisoryx_refsource_REDHAT
    http://secunia.com/advisories/25743 third-party-advisoryx_refsource_SECUNIA
    http://support.avaya.com/elmodocs2/security/ASA-2… x_refsource_CONFIRM
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://www.securityfocus.com/bid/23742 vdb-entryx_refsource_BID
    Date Public
    2006-10-02 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T20:57:39.637Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "25098",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/25098"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=171838"
              },
              {
                "name": "RHSA-2007:0252",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2007-0252.html"
              },
              {
                "name": "25743",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/25743"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://support.avaya.com/elmodocs2/security/ASA-2007-248.htm"
              },
              {
                "name": "oval:org.mitre.oval:def:11499",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11499"
              },
              {
                "name": "23742",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/23742"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2006-10-02T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not reject the \"localhost.localdomain\" domain name for e-mail messages that come from external hosts, which might allow remote attackers to spoof messages."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-10-10T00:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "25098",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/25098"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=171838"
            },
            {
              "name": "RHSA-2007:0252",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2007-0252.html"
            },
            {
              "name": "25743",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/25743"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://support.avaya.com/elmodocs2/security/ASA-2007-248.htm"
            },
            {
              "name": "oval:org.mitre.oval:def:11499",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11499"
            },
            {
              "name": "23742",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/23742"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2006-7176",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not reject the \"localhost.localdomain\" domain name for e-mail messages that come from external hosts, which might allow remote attackers to spoof messages."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "25098",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/25098"
                },
                {
                  "name": "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=171838",
                  "refsource": "MISC",
                  "url": "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=171838"
                },
                {
                  "name": "RHSA-2007:0252",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2007-0252.html"
                },
                {
                  "name": "25743",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/25743"
                },
                {
                  "name": "http://support.avaya.com/elmodocs2/security/ASA-2007-248.htm",
                  "refsource": "CONFIRM",
                  "url": "http://support.avaya.com/elmodocs2/security/ASA-2007-248.htm"
                },
                {
                  "name": "oval:org.mitre.oval:def:11499",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11499"
                },
                {
                  "name": "23742",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/23742"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2006-7176",
        "datePublished": "2007-03-27T23:00:00.000Z",
        "dateReserved": "2007-03-27T00:00:00.000Z",
        "dateUpdated": "2024-08-07T20:57:39.637Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2006-4434 (GCVE-0-2006-4434)

    Vulnerability from nvd – Published: 2006-08-29 00:00 – Updated: 2024-08-07 19:06
    VLAI
    Summary
    Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected."
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.openbsd.org/errata.html#sendmail3 vendor-advisoryx_refsource_OPENBSD
    http://www.attrition.org/pipermail/vim/2006-Augus… mailing-listx_refsource_VIM
    http://securitytracker.com/id?1016753 vdb-entryx_refsource_SECTRACK
    http://secunia.com/advisories/21637 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2006/3994 vdb-entryx_refsource_VUPEN
    http://www.osvdb.org/28193 vdb-entryx_refsource_OSVDB
    http://secunia.com/advisories/21749 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/21700 third-party-advisoryx_refsource_SECUNIA
    http://www.debian.org/security/2006/dsa-1164 vendor-advisoryx_refsource_DEBIAN
    http://secunia.com/advisories/21641 third-party-advisoryx_refsource_SECUNIA
    http://www.sendmail.org/releases/8.13.8.html x_refsource_CONFIRM
    http://www.vupen.com/english/advisories/2006/3393 vdb-entryx_refsource_VUPEN
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://www.securityfocus.com/bid/19714 vdb-entryx_refsource_BID
    http://www.novell.com/linux/security/advisories/2… vendor-advisoryx_refsource_SUSE
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://secunia.com/advisories/22369 third-party-advisoryx_refsource_SECUNIA
    http://www.openbsd.org/errata38.html#sendmail3 vendor-advisoryx_refsource_OPENBSD
    http://secunia.com/advisories/21696 third-party-advisoryx_refsource_SECUNIA
    Date Public
    2006-08-09 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T19:06:07.644Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "[3.9] 20060825 005: SECURITY FIX: August 25, 2006",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_OPENBSD",
                  "x_transferred"
                ],
                "url": "http://www.openbsd.org/errata.html#sendmail3"
              },
              {
                "name": "20060829 Sendmail vendor dispute - CVE-2006-4434 (fwd)",
                "tags": [
                  "mailing-list",
                  "x_refsource_VIM",
                  "x_transferred"
                ],
                "url": "http://www.attrition.org/pipermail/vim/2006-August/000999.html"
              },
              {
                "name": "1016753",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://securitytracker.com/id?1016753"
              },
              {
                "name": "21637",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/21637"
              },
              {
                "name": "ADV-2006-3994",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/3994"
              },
              {
                "name": "28193",
                "tags": [
                  "vdb-entry",
                  "x_refsource_OSVDB",
                  "x_transferred"
                ],
                "url": "http://www.osvdb.org/28193"
              },
              {
                "name": "21749",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/21749"
              },
              {
                "name": "21700",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/21700"
              },
              {
                "name": "DSA-1164",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2006/dsa-1164"
              },
              {
                "name": "21641",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/21641"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.sendmail.org/releases/8.13.8.html"
              },
              {
                "name": "ADV-2006-3393",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/3393"
              },
              {
                "name": "MDKSA-2006:156",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:156"
              },
              {
                "name": "19714",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/19714"
              },
              {
                "name": "SUSE-SR:2006:021",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://www.novell.com/linux/security/advisories/2006_21_sr.html"
              },
              {
                "name": "102664",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102664-1"
              },
              {
                "name": "22369",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/22369"
              },
              {
                "name": "[3.8] 20060825 010: SECURITY FIX: August 25, 2006",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_OPENBSD",
                  "x_transferred"
                ],
                "url": "http://www.openbsd.org/errata38.html#sendmail3"
              },
              {
                "name": "21696",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/21696"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2006-08-09T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long \"header line\", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying \"The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected.\""
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2006-09-02T09:00:00.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "[3.9] 20060825 005: SECURITY FIX: August 25, 2006",
              "tags": [
                "vendor-advisory",
                "x_refsource_OPENBSD"
              ],
              "url": "http://www.openbsd.org/errata.html#sendmail3"
            },
            {
              "name": "20060829 Sendmail vendor dispute - CVE-2006-4434 (fwd)",
              "tags": [
                "mailing-list",
                "x_refsource_VIM"
              ],
              "url": "http://www.attrition.org/pipermail/vim/2006-August/000999.html"
            },
            {
              "name": "1016753",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://securitytracker.com/id?1016753"
            },
            {
              "name": "21637",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/21637"
            },
            {
              "name": "ADV-2006-3994",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/3994"
            },
            {
              "name": "28193",
              "tags": [
                "vdb-entry",
                "x_refsource_OSVDB"
              ],
              "url": "http://www.osvdb.org/28193"
            },
            {
              "name": "21749",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/21749"
            },
            {
              "name": "21700",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/21700"
            },
            {
              "name": "DSA-1164",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2006/dsa-1164"
            },
            {
              "name": "21641",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/21641"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.sendmail.org/releases/8.13.8.html"
            },
            {
              "name": "ADV-2006-3393",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/3393"
            },
            {
              "name": "MDKSA-2006:156",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:156"
            },
            {
              "name": "19714",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/19714"
            },
            {
              "name": "SUSE-SR:2006:021",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://www.novell.com/linux/security/advisories/2006_21_sr.html"
            },
            {
              "name": "102664",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102664-1"
            },
            {
              "name": "22369",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/22369"
            },
            {
              "name": "[3.8] 20060825 010: SECURITY FIX: August 25, 2006",
              "tags": [
                "vendor-advisory",
                "x_refsource_OPENBSD"
              ],
              "url": "http://www.openbsd.org/errata38.html#sendmail3"
            },
            {
              "name": "21696",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/21696"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2006-4434",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long \"header line\", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying \"The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected.\""
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "[3.9] 20060825 005: SECURITY FIX: August 25, 2006",
                  "refsource": "OPENBSD",
                  "url": "http://www.openbsd.org/errata.html#sendmail3"
                },
                {
                  "name": "20060829 Sendmail vendor dispute - CVE-2006-4434 (fwd)",
                  "refsource": "VIM",
                  "url": "http://www.attrition.org/pipermail/vim/2006-August/000999.html"
                },
                {
                  "name": "1016753",
                  "refsource": "SECTRACK",
                  "url": "http://securitytracker.com/id?1016753"
                },
                {
                  "name": "21637",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/21637"
                },
                {
                  "name": "ADV-2006-3994",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/3994"
                },
                {
                  "name": "28193",
                  "refsource": "OSVDB",
                  "url": "http://www.osvdb.org/28193"
                },
                {
                  "name": "21749",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/21749"
                },
                {
                  "name": "21700",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/21700"
                },
                {
                  "name": "DSA-1164",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2006/dsa-1164"
                },
                {
                  "name": "21641",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/21641"
                },
                {
                  "name": "http://www.sendmail.org/releases/8.13.8.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.sendmail.org/releases/8.13.8.html"
                },
                {
                  "name": "ADV-2006-3393",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/3393"
                },
                {
                  "name": "MDKSA-2006:156",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:156"
                },
                {
                  "name": "19714",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/19714"
                },
                {
                  "name": "SUSE-SR:2006:021",
                  "refsource": "SUSE",
                  "url": "http://www.novell.com/linux/security/advisories/2006_21_sr.html"
                },
                {
                  "name": "102664",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102664-1"
                },
                {
                  "name": "22369",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/22369"
                },
                {
                  "name": "[3.8] 20060825 010: SECURITY FIX: August 25, 2006",
                  "refsource": "OPENBSD",
                  "url": "http://www.openbsd.org/errata38.html#sendmail3"
                },
                {
                  "name": "21696",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/21696"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2006-4434",
        "datePublished": "2006-08-29T00:00:00.000Z",
        "dateReserved": "2006-08-28T00:00:00.000Z",
        "dateUpdated": "2024-08-07T19:06:07.644Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2006-1173 (GCVE-0-2006-1173)

    Vulnerability from nvd – Published: 2006-06-07 23:00 – Updated: 2024-08-07 17:03
    VLAI
    Summary
    Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www-1.ibm.com/support/search.wss?rs=0&q=IY… vendor-advisoryx_refsource_AIXAPAR
    http://itrc.hp.com/service/cki/docDisplay.do?docI… vendor-advisoryx_refsource_HP
    http://www.debian.org/security/2006/dsa-1155 vendor-advisoryx_refsource_DEBIAN
    http://www.openbsd.org/errata38.html#sendmail2 vendor-advisoryx_refsource_OPENBSD
    http://secunia.com/advisories/20684 third-party-advisoryx_refsource_SECUNIA
    http://www.securityfocus.com/archive/1/442939/100… vendor-advisoryx_refsource_HP
    http://www.vupen.com/english/advisories/2006/2388 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/20726 third-party-advisoryx_refsource_SECUNIA
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://www.vupen.com/english/advisories/2006/2351 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/21327 third-party-advisoryx_refsource_SECUNIA
    http://www.redhat.com/support/errata/RHSA-2006-05… vendor-advisoryx_refsource_REDHAT
    http://www.vupen.com/english/advisories/2006/2389 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/21647 third-party-advisoryx_refsource_SECUNIA
    http://www.fortinet.com/FortiGuardCenter/advisory… x_refsource_CONFIRM
    https://issues.rpath.com/browse/RPL-526 x_refsource_CONFIRM
    http://secunia.com/advisories/20651 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/20683 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/20650 third-party-advisoryx_refsource_SECUNIA
    http://support.avaya.com/elmodocs2/security/ASA-2… x_refsource_CONFIRM
    http://secunia.com/advisories/20782 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2006/3135 vdb-entryx_refsource_VUPEN
    http://securitytracker.com/id?1016295 vdb-entryx_refsource_SECTRACK
    http://secunia.com/advisories/20694 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/20473 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2006/2189 vdb-entryx_refsource_VUPEN
    http://www.securityfocus.com/archive/1/440744/100… mailing-listx_refsource_BUGTRAQ
    ftp://patches.sgi.com/support/free/security/advis… vendor-advisoryx_refsource_SGI
    http://www.vupen.com/english/advisories/2006/2798 vdb-entryx_refsource_VUPEN
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://www.sendmail.com/security/advisories/SA-20… x_refsource_CONFIRM
    ftp://patches.sgi.com/support/free/security/advis… vendor-advisoryx_refsource_SGI
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    http://secunia.com/advisories/20673 third-party-advisoryx_refsource_SECUNIA
    http://www.f-secure.com/security/fsc-2006-5.shtml x_refsource_CONFIRM
    http://www.securityfocus.com/archive/1/438241/100… mailing-listx_refsource_BUGTRAQ
    http://secunia.com/advisories/21612 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/20654 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2006/2390 vdb-entryx_refsource_VUPEN
    http://slackware.com/security/viewer.php?l=slackw… vendor-advisoryx_refsource_SLACKWARE
    http://www.gentoo.org/security/en/glsa/glsa-20060… vendor-advisoryx_refsource_GENTOO
    http://www.securityfocus.com/bid/18433 vdb-entryx_refsource_BID
    http://secunia.com/advisories/20675 third-party-advisoryx_refsource_SECUNIA
    http://lists.suse.com/archive/suse-security-annou… vendor-advisoryx_refsource_SUSE
    ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories… vendor-advisoryx_refsource_FREEBSD
    http://www.securityfocus.com/archive/1/437928/100… mailing-listx_refsource_BUGTRAQ
    http://www.kb.cert.org/vuls/id/146718 third-party-advisoryx_refsource_CERT-VN
    http://secunia.com/advisories/15779 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/20641 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/20679 third-party-advisoryx_refsource_SECUNIA
    http://www.osvdb.org/26197 vdb-entryx_refsource_OSVDB
    http://secunia.com/advisories/21042 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/21160 third-party-advisoryx_refsource_SECUNIA
    http://www-1.ibm.com/support/search.wss?rs=0&q=IY… vendor-advisoryx_refsource_AIXAPAR
    http://www.securityfocus.com/archive/1/438330/100… mailing-listx_refsource_BUGTRAQ
    Date Public
    2006-06-06 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T17:03:28.441Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "IY85415",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_AIXAPAR",
                  "x_transferred"
                ],
                "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY85415\u0026apar=only"
              },
              {
                "name": "HPSBTU02116",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
              },
              {
                "name": "DSA-1155",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2006/dsa-1155"
              },
              {
                "name": "[3.8] 008: SECURITY FIX: June 15, 2006",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_OPENBSD",
                  "x_transferred"
                ],
                "url": "http://www.openbsd.org/errata38.html#sendmail2"
              },
              {
                "name": "20684",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20684"
              },
              {
                "name": "HPSBUX02124",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/442939/100/0/threaded"
              },
              {
                "name": "ADV-2006-2388",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/2388"
              },
              {
                "name": "20726",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20726"
              },
              {
                "name": "oval:org.mitre.oval:def:11253",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11253"
              },
              {
                "name": "ADV-2006-2351",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/2351"
              },
              {
                "name": "21327",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/21327"
              },
              {
                "name": "RHSA-2006:0515",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2006-0515.html"
              },
              {
                "name": "ADV-2006-2389",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/2389"
              },
              {
                "name": "21647",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/21647"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-18.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://issues.rpath.com/browse/RPL-526"
              },
              {
                "name": "20651",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20651"
              },
              {
                "name": "20683",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20683"
              },
              {
                "name": "20650",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20650"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://support.avaya.com/elmodocs2/security/ASA-2006-148.htm"
              },
              {
                "name": "20782",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20782"
              },
              {
                "name": "ADV-2006-3135",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/3135"
              },
              {
                "name": "1016295",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://securitytracker.com/id?1016295"
              },
              {
                "name": "20694",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20694"
              },
              {
                "name": "20473",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20473"
              },
              {
                "name": "ADV-2006-2189",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/2189"
              },
              {
                "name": "20060721 rPSA-2006-0134-1 sendmail sendmail-cf",
                "tags": [
                  "mailing-list",
                  "x_refsource_BUGTRAQ",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/440744/100/0/threaded"
              },
              {
                "name": "20060601-01-P",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SGI",
                  "x_transferred"
                ],
                "url": "ftp://patches.sgi.com/support/free/security/advisories/20060601-01-P"
              },
              {
                "name": "ADV-2006-2798",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/2798"
              },
              {
                "name": "102460",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102460-1"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.sendmail.com/security/advisories/SA-200605-01.txt.asc"
              },
              {
                "name": "20060602-01-U",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SGI",
                  "x_transferred"
                ],
                "url": "ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc"
              },
              {
                "name": "MDKSA-2006:104",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:104"
              },
              {
                "name": "sendmail-multipart-mime-dos(27128)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27128"
              },
              {
                "name": "20673",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20673"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.f-secure.com/security/fsc-2006-5.shtml"
              },
              {
                "name": "20060621 Re: Sendmail MIME DoS vulnerability",
                "tags": [
                  "mailing-list",
                  "x_refsource_BUGTRAQ",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/438241/100/0/threaded"
              },
              {
                "name": "21612",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/21612"
              },
              {
                "name": "20654",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20654"
              },
              {
                "name": "ADV-2006-2390",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/2390"
              },
              {
                "name": "SSA:2006-166-01",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SLACKWARE",
                  "x_transferred"
                ],
                "url": "http://slackware.com/security/viewer.php?l=slackware-security\u0026y=2006\u0026m=slackware-security.631382"
              },
              {
                "name": "GLSA-200606-19",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://www.gentoo.org/security/en/glsa/glsa-200606-19.xml"
              },
              {
                "name": "18433",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/18433"
              },
              {
                "name": "20675",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20675"
              },
              {
                "name": "SUSE-SA:2006:032",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.suse.com/archive/suse-security-announce/2006-Jun/0006.html"
              },
              {
                "name": "FreeBSD-SA-06:17.sendmail",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FREEBSD",
                  "x_transferred"
                ],
                "url": "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:17.sendmail.asc"
              },
              {
                "name": "20060620 Sendmail MIME DoS vulnerability",
                "tags": [
                  "mailing-list",
                  "x_refsource_BUGTRAQ",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/437928/100/0/threaded"
              },
              {
                "name": "SSRT061159",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/442939/100/0/threaded"
              },
              {
                "name": "VU#146718",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_CERT-VN",
                  "x_transferred"
                ],
                "url": "http://www.kb.cert.org/vuls/id/146718"
              },
              {
                "name": "SSRT061135",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
              },
              {
                "name": "15779",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/15779"
              },
              {
                "name": "20641",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20641"
              },
              {
                "name": "20679",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20679"
              },
              {
                "name": "26197",
                "tags": [
                  "vdb-entry",
                  "x_refsource_OSVDB",
                  "x_transferred"
                ],
                "url": "http://www.osvdb.org/26197"
              },
              {
                "name": "21042",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/21042"
              },
              {
                "name": "21160",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/21160"
              },
              {
                "name": "IY85930",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_AIXAPAR",
                  "x_transferred"
                ],
                "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY85930\u0026apar=only"
              },
              {
                "name": "20060624 Re: Sendmail MIME DoS vulnerability",
                "tags": [
                  "mailing-list",
                  "x_refsource_BUGTRAQ",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/438330/100/0/threaded"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2006-06-06T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-10-18T14:57:01.000Z",
            "orgId": "37e5125f-f79b-445b-8fad-9564f167944b",
            "shortName": "certcc"
          },
          "references": [
            {
              "name": "IY85415",
              "tags": [
                "vendor-advisory",
                "x_refsource_AIXAPAR"
              ],
              "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY85415\u0026apar=only"
            },
            {
              "name": "HPSBTU02116",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
            },
            {
              "name": "DSA-1155",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2006/dsa-1155"
            },
            {
              "name": "[3.8] 008: SECURITY FIX: June 15, 2006",
              "tags": [
                "vendor-advisory",
                "x_refsource_OPENBSD"
              ],
              "url": "http://www.openbsd.org/errata38.html#sendmail2"
            },
            {
              "name": "20684",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20684"
            },
            {
              "name": "HPSBUX02124",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://www.securityfocus.com/archive/1/442939/100/0/threaded"
            },
            {
              "name": "ADV-2006-2388",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/2388"
            },
            {
              "name": "20726",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20726"
            },
            {
              "name": "oval:org.mitre.oval:def:11253",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11253"
            },
            {
              "name": "ADV-2006-2351",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/2351"
            },
            {
              "name": "21327",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/21327"
            },
            {
              "name": "RHSA-2006:0515",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2006-0515.html"
            },
            {
              "name": "ADV-2006-2389",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/2389"
            },
            {
              "name": "21647",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/21647"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-18.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://issues.rpath.com/browse/RPL-526"
            },
            {
              "name": "20651",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20651"
            },
            {
              "name": "20683",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20683"
            },
            {
              "name": "20650",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20650"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://support.avaya.com/elmodocs2/security/ASA-2006-148.htm"
            },
            {
              "name": "20782",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20782"
            },
            {
              "name": "ADV-2006-3135",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/3135"
            },
            {
              "name": "1016295",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://securitytracker.com/id?1016295"
            },
            {
              "name": "20694",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20694"
            },
            {
              "name": "20473",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20473"
            },
            {
              "name": "ADV-2006-2189",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/2189"
            },
            {
              "name": "20060721 rPSA-2006-0134-1 sendmail sendmail-cf",
              "tags": [
                "mailing-list",
                "x_refsource_BUGTRAQ"
              ],
              "url": "http://www.securityfocus.com/archive/1/440744/100/0/threaded"
            },
            {
              "name": "20060601-01-P",
              "tags": [
                "vendor-advisory",
                "x_refsource_SGI"
              ],
              "url": "ftp://patches.sgi.com/support/free/security/advisories/20060601-01-P"
            },
            {
              "name": "ADV-2006-2798",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/2798"
            },
            {
              "name": "102460",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102460-1"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.sendmail.com/security/advisories/SA-200605-01.txt.asc"
            },
            {
              "name": "20060602-01-U",
              "tags": [
                "vendor-advisory",
                "x_refsource_SGI"
              ],
              "url": "ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc"
            },
            {
              "name": "MDKSA-2006:104",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:104"
            },
            {
              "name": "sendmail-multipart-mime-dos(27128)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27128"
            },
            {
              "name": "20673",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20673"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.f-secure.com/security/fsc-2006-5.shtml"
            },
            {
              "name": "20060621 Re: Sendmail MIME DoS vulnerability",
              "tags": [
                "mailing-list",
                "x_refsource_BUGTRAQ"
              ],
              "url": "http://www.securityfocus.com/archive/1/438241/100/0/threaded"
            },
            {
              "name": "21612",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/21612"
            },
            {
              "name": "20654",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20654"
            },
            {
              "name": "ADV-2006-2390",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/2390"
            },
            {
              "name": "SSA:2006-166-01",
              "tags": [
                "vendor-advisory",
                "x_refsource_SLACKWARE"
              ],
              "url": "http://slackware.com/security/viewer.php?l=slackware-security\u0026y=2006\u0026m=slackware-security.631382"
            },
            {
              "name": "GLSA-200606-19",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://www.gentoo.org/security/en/glsa/glsa-200606-19.xml"
            },
            {
              "name": "18433",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/18433"
            },
            {
              "name": "20675",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20675"
            },
            {
              "name": "SUSE-SA:2006:032",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.suse.com/archive/suse-security-announce/2006-Jun/0006.html"
            },
            {
              "name": "FreeBSD-SA-06:17.sendmail",
              "tags": [
                "vendor-advisory",
                "x_refsource_FREEBSD"
              ],
              "url": "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:17.sendmail.asc"
            },
            {
              "name": "20060620 Sendmail MIME DoS vulnerability",
              "tags": [
                "mailing-list",
                "x_refsource_BUGTRAQ"
              ],
              "url": "http://www.securityfocus.com/archive/1/437928/100/0/threaded"
            },
            {
              "name": "SSRT061159",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://www.securityfocus.com/archive/1/442939/100/0/threaded"
            },
            {
              "name": "VU#146718",
              "tags": [
                "third-party-advisory",
                "x_refsource_CERT-VN"
              ],
              "url": "http://www.kb.cert.org/vuls/id/146718"
            },
            {
              "name": "SSRT061135",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
            },
            {
              "name": "15779",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/15779"
            },
            {
              "name": "20641",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20641"
            },
            {
              "name": "20679",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20679"
            },
            {
              "name": "26197",
              "tags": [
                "vdb-entry",
                "x_refsource_OSVDB"
              ],
              "url": "http://www.osvdb.org/26197"
            },
            {
              "name": "21042",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/21042"
            },
            {
              "name": "21160",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/21160"
            },
            {
              "name": "IY85930",
              "tags": [
                "vendor-advisory",
                "x_refsource_AIXAPAR"
              ],
              "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY85930\u0026apar=only"
            },
            {
              "name": "20060624 Re: Sendmail MIME DoS vulnerability",
              "tags": [
                "mailing-list",
                "x_refsource_BUGTRAQ"
              ],
              "url": "http://www.securityfocus.com/archive/1/438330/100/0/threaded"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cert@cert.org",
              "ID": "CVE-2006-1173",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "IY85415",
                  "refsource": "AIXAPAR",
                  "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY85415\u0026apar=only"
                },
                {
                  "name": "HPSBTU02116",
                  "refsource": "HP",
                  "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
                },
                {
                  "name": "DSA-1155",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2006/dsa-1155"
                },
                {
                  "name": "[3.8] 008: SECURITY FIX: June 15, 2006",
                  "refsource": "OPENBSD",
                  "url": "http://www.openbsd.org/errata38.html#sendmail2"
                },
                {
                  "name": "20684",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20684"
                },
                {
                  "name": "HPSBUX02124",
                  "refsource": "HP",
                  "url": "http://www.securityfocus.com/archive/1/442939/100/0/threaded"
                },
                {
                  "name": "ADV-2006-2388",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/2388"
                },
                {
                  "name": "20726",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20726"
                },
                {
                  "name": "oval:org.mitre.oval:def:11253",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11253"
                },
                {
                  "name": "ADV-2006-2351",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/2351"
                },
                {
                  "name": "21327",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/21327"
                },
                {
                  "name": "RHSA-2006:0515",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2006-0515.html"
                },
                {
                  "name": "ADV-2006-2389",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/2389"
                },
                {
                  "name": "21647",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/21647"
                },
                {
                  "name": "http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-18.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-18.html"
                },
                {
                  "name": "https://issues.rpath.com/browse/RPL-526",
                  "refsource": "CONFIRM",
                  "url": "https://issues.rpath.com/browse/RPL-526"
                },
                {
                  "name": "20651",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20651"
                },
                {
                  "name": "20683",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20683"
                },
                {
                  "name": "20650",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20650"
                },
                {
                  "name": "http://support.avaya.com/elmodocs2/security/ASA-2006-148.htm",
                  "refsource": "CONFIRM",
                  "url": "http://support.avaya.com/elmodocs2/security/ASA-2006-148.htm"
                },
                {
                  "name": "20782",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20782"
                },
                {
                  "name": "ADV-2006-3135",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/3135"
                },
                {
                  "name": "1016295",
                  "refsource": "SECTRACK",
                  "url": "http://securitytracker.com/id?1016295"
                },
                {
                  "name": "20694",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20694"
                },
                {
                  "name": "20473",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20473"
                },
                {
                  "name": "ADV-2006-2189",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/2189"
                },
                {
                  "name": "20060721 rPSA-2006-0134-1 sendmail sendmail-cf",
                  "refsource": "BUGTRAQ",
                  "url": "http://www.securityfocus.com/archive/1/440744/100/0/threaded"
                },
                {
                  "name": "20060601-01-P",
                  "refsource": "SGI",
                  "url": "ftp://patches.sgi.com/support/free/security/advisories/20060601-01-P"
                },
                {
                  "name": "ADV-2006-2798",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/2798"
                },
                {
                  "name": "102460",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102460-1"
                },
                {
                  "name": "http://www.sendmail.com/security/advisories/SA-200605-01.txt.asc",
                  "refsource": "CONFIRM",
                  "url": "http://www.sendmail.com/security/advisories/SA-200605-01.txt.asc"
                },
                {
                  "name": "20060602-01-U",
                  "refsource": "SGI",
                  "url": "ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc"
                },
                {
                  "name": "MDKSA-2006:104",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:104"
                },
                {
                  "name": "sendmail-multipart-mime-dos(27128)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27128"
                },
                {
                  "name": "20673",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20673"
                },
                {
                  "name": "http://www.f-secure.com/security/fsc-2006-5.shtml",
                  "refsource": "CONFIRM",
                  "url": "http://www.f-secure.com/security/fsc-2006-5.shtml"
                },
                {
                  "name": "20060621 Re: Sendmail MIME DoS vulnerability",
                  "refsource": "BUGTRAQ",
                  "url": "http://www.securityfocus.com/archive/1/438241/100/0/threaded"
                },
                {
                  "name": "21612",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/21612"
                },
                {
                  "name": "20654",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20654"
                },
                {
                  "name": "ADV-2006-2390",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/2390"
                },
                {
                  "name": "SSA:2006-166-01",
                  "refsource": "SLACKWARE",
                  "url": "http://slackware.com/security/viewer.php?l=slackware-security\u0026y=2006\u0026m=slackware-security.631382"
                },
                {
                  "name": "GLSA-200606-19",
                  "refsource": "GENTOO",
                  "url": "http://www.gentoo.org/security/en/glsa/glsa-200606-19.xml"
                },
                {
                  "name": "18433",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/18433"
                },
                {
                  "name": "20675",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20675"
                },
                {
                  "name": "SUSE-SA:2006:032",
                  "refsource": "SUSE",
                  "url": "http://lists.suse.com/archive/suse-security-announce/2006-Jun/0006.html"
                },
                {
                  "name": "FreeBSD-SA-06:17.sendmail",
                  "refsource": "FREEBSD",
                  "url": "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:17.sendmail.asc"
                },
                {
                  "name": "20060620 Sendmail MIME DoS vulnerability",
                  "refsource": "BUGTRAQ",
                  "url": "http://www.securityfocus.com/archive/1/437928/100/0/threaded"
                },
                {
                  "name": "SSRT061159",
                  "refsource": "HP",
                  "url": "http://www.securityfocus.com/archive/1/442939/100/0/threaded"
                },
                {
                  "name": "VU#146718",
                  "refsource": "CERT-VN",
                  "url": "http://www.kb.cert.org/vuls/id/146718"
                },
                {
                  "name": "SSRT061135",
                  "refsource": "HP",
                  "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
                },
                {
                  "name": "15779",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/15779"
                },
                {
                  "name": "20641",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20641"
                },
                {
                  "name": "20679",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20679"
                },
                {
                  "name": "26197",
                  "refsource": "OSVDB",
                  "url": "http://www.osvdb.org/26197"
                },
                {
                  "name": "21042",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/21042"
                },
                {
                  "name": "21160",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/21160"
                },
                {
                  "name": "IY85930",
                  "refsource": "AIXAPAR",
                  "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY85930\u0026apar=only"
                },
                {
                  "name": "20060624 Re: Sendmail MIME DoS vulnerability",
                  "refsource": "BUGTRAQ",
                  "url": "http://www.securityfocus.com/archive/1/438330/100/0/threaded"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "37e5125f-f79b-445b-8fad-9564f167944b",
        "assignerShortName": "certcc",
        "cveId": "CVE-2006-1173",
        "datePublished": "2006-06-07T23:00:00.000Z",
        "dateReserved": "2006-03-12T00:00:00.000Z",
        "dateUpdated": "2024-08-07T17:03:28.441Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2006-0058 (GCVE-0-2006-0058)

    Vulnerability from nvd – Published: 2006-03-22 20:00 – Updated: 2024-08-07 16:18
    VLAI
    Summary
    Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.vupen.com/english/advisories/2006/1529 vdb-entryx_refsource_VUPEN
    http://itrc.hp.com/service/cki/docDisplay.do?docI… vendor-advisoryx_refsource_HP
    http://secunia.com/advisories/19450 third-party-advisoryx_refsource_SECUNIA
    http://www.debian.org/security/2006/dsa-1015 vendor-advisoryx_refsource_DEBIAN
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://www14.software.ibm.com/webapp/set2/sas/f/h… x_refsource_CONFIRM
    http://www.openbsd.org/errata38.html#sendmail vendor-advisoryx_refsource_OPENBSD
    http://www.kb.cert.org/vuls/id/834865 third-party-advisoryx_refsource_CERT-VN
    ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006… vendor-advisoryx_refsource_SCO
    http://secunia.com/advisories/19342 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2006/1049 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/19774 third-party-advisoryx_refsource_SECUNIA
    ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories… vendor-advisoryx_refsource_FREEBSD
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    ftp://patches.sgi.com/support/free/security/advis… vendor-advisoryx_refsource_SGI
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://secunia.com/advisories/19404 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/19367 third-party-advisoryx_refsource_SECUNIA
    http://www.openpkg.org/security/advisories/OpenPK… vendor-advisoryx_refsource_OPENPKG
    http://www.vupen.com/english/advisories/2006/1051 vdb-entryx_refsource_VUPEN
    http://www.securityfocus.com/archive/1/428536/100… mailing-listx_refsource_BUGTRAQ
    http://www.f-secure.com/security/fsc-2006-2.shtml x_refsource_CONFIRM
    http://securityreason.com/securityalert/743 third-party-advisoryx_refsource_SREASON
    http://securitytracker.com/id?1015801 vdb-entryx_refsource_SECTRACK
    http://h20000.www2.hp.com/bizsupport/TechSupport/… vendor-advisoryx_refsource_HP
    http://secunia.com/advisories/19363 third-party-advisoryx_refsource_SECUNIA
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    http://www.us-cert.gov/cas/techalerts/TA06-081A.html third-party-advisoryx_refsource_CERT
    http://secunia.com/advisories/20723 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/20243 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/19407 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2006/2189 vdb-entryx_refsource_VUPEN
    http://www.redhat.com/archives/fedora-announce-li… vendor-advisoryx_refsource_FEDORA
    ftp://patches.sgi.com/support/free/security/advis… vendor-advisoryx_refsource_SGI
    http://www.iss.net/threats/216.html third-party-advisoryx_refsource_ISS
    http://secunia.com/advisories/19466 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/19368 third-party-advisoryx_refsource_SECUNIA
    http://support.avaya.com/elmodocs2/security/ASA-2… x_refsource_CONFIRM
    http://www.ciac.org/ciac/bulletins/q-151.shtml third-party-advisorygovernment-resourcex_refsource_CIAC
    http://support.avaya.com/elmodocs2/security/ASA-2… x_refsource_CONFIRM
    http://secunia.com/advisories/19345 third-party-advisoryx_refsource_SECUNIA
    http://securityreason.com/securityalert/612 third-party-advisoryx_refsource_SREASON
    http://www.redhat.com/archives/fedora-announce-li… vendor-advisoryx_refsource_FEDORA
    http://secunia.com/advisories/19346 third-party-advisoryx_refsource_SECUNIA
    http://slackware.com/security/viewer.php?l=slackw… vendor-advisoryx_refsource_SLACKWARE
    http://www-1.ibm.com/support/search.wss?rs=0&q=IY… vendor-advisoryx_refsource_AIXAPAR
    http://www14.software.ibm.com/webapp/set2/subscri… x_refsource_CONFIRM
    http://www.gentoo.org/security/en/glsa/glsa-20060… vendor-advisoryx_refsource_GENTOO
    http://www-1.ibm.com/support/search.wss?rs=0&q=IY… vendor-advisoryx_refsource_AIXAPAR
    http://www-1.ibm.com/support/search.wss?rs=0&q=IY… vendor-advisoryx_refsource_AIXAPAR
    http://www.vupen.com/english/advisories/2006/1068 vdb-entryx_refsource_VUPEN
    http://www.redhat.com/support/errata/RHSA-2006-02… vendor-advisoryx_refsource_REDHAT
    http://www.vupen.com/english/advisories/2006/2490 vdb-entryx_refsource_VUPEN
    http://www.vupen.com/english/advisories/2006/1072 vdb-entryx_refsource_VUPEN
    http://www.securityfocus.com/archive/1/428656/100… vendor-advisoryx_refsource_FEDORA
    http://secunia.com/advisories/19360 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/19532 third-party-advisoryx_refsource_SECUNIA
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://secunia.com/advisories/19361 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/19676 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/19356 third-party-advisoryx_refsource_SECUNIA
    http://www.novell.com/linux/security/advisories/2… vendor-advisoryx_refsource_SUSE
    http://www.osvdb.org/24037 vdb-entryx_refsource_OSVDB
    http://secunia.com/advisories/19349 third-party-advisoryx_refsource_SECUNIA
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://secunia.com/advisories/19394 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2006/1139 vdb-entryx_refsource_VUPEN
    http://www.vupen.com/english/advisories/2006/1157 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/19533 third-party-advisoryx_refsource_SECUNIA
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    ftp://ftp.netbsd.org/pub/NetBSD/security/advisori… vendor-advisoryx_refsource_NETBSD
    http://www.securityfocus.com/bid/17192 vdb-entryx_refsource_BID
    http://www.redhat.com/support/errata/RHSA-2006-02… vendor-advisoryx_refsource_REDHAT
    http://www.sendmail.com/company/advisory/index.shtml x_refsource_CONFIRM
    Date Public
    2006-03-22 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T16:18:20.809Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "ADV-2006-1529",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/1529"
              },
              {
                "name": "HPSBTU02116",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
              },
              {
                "name": "19450",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19450"
              },
              {
                "name": "DSA-1015",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2006/dsa-1015"
              },
              {
                "name": "MDKSA-2006:058",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:058"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688"
              },
              {
                "name": "[3.8] 006: SECURITY FIX: March 25, 2006",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_OPENBSD",
                  "x_transferred"
                ],
                "url": "http://www.openbsd.org/errata38.html#sendmail"
              },
              {
                "name": "VU#834865",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_CERT-VN",
                  "x_transferred"
                ],
                "url": "http://www.kb.cert.org/vuls/id/834865"
              },
              {
                "name": "SCOSA-2006.24",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SCO",
                  "x_transferred"
                ],
                "url": "ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.24/SCOSA-2006.24.txt"
              },
              {
                "name": "19342",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19342"
              },
              {
                "name": "ADV-2006-1049",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/1049"
              },
              {
                "name": "19774",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19774"
              },
              {
                "name": "FreeBSD-SA-06:13",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FREEBSD",
                  "x_transferred"
                ],
                "url": "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:13.sendmail.asc"
              },
              {
                "name": "oval:org.mitre.oval:def:11074",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11074"
              },
              {
                "name": "20060401-01-U",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SGI",
                  "x_transferred"
                ],
                "url": "ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U"
              },
              {
                "name": "200494",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-66-200494-1"
              },
              {
                "name": "19404",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19404"
              },
              {
                "name": "19367",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19367"
              },
              {
                "name": "OpenPKG-SA-2006.007",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_OPENPKG",
                  "x_transferred"
                ],
                "url": "http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.007-sendmail.html"
              },
              {
                "name": "ADV-2006-1051",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/1051"
              },
              {
                "name": "20060322 sendmail vuln advisories (CVE-2006-0058)",
                "tags": [
                  "mailing-list",
                  "x_refsource_BUGTRAQ",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/428536/100/0/threaded"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.f-secure.com/security/fsc-2006-2.shtml"
              },
              {
                "name": "743",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SREASON",
                  "x_transferred"
                ],
                "url": "http://securityreason.com/securityalert/743"
              },
              {
                "name": "1015801",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://securitytracker.com/id?1015801"
              },
              {
                "name": "HPSBUX02108",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00629555"
              },
              {
                "name": "19363",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19363"
              },
              {
                "name": "smtp-timeout-bo(24584)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/24584"
              },
              {
                "name": "TA06-081A",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_CERT",
                  "x_transferred"
                ],
                "url": "http://www.us-cert.gov/cas/techalerts/TA06-081A.html"
              },
              {
                "name": "20723",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20723"
              },
              {
                "name": "20243",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20243"
              },
              {
                "name": "19407",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19407"
              },
              {
                "name": "ADV-2006-2189",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/2189"
              },
              {
                "name": "FEDORA-2006-194",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00017.html"
              },
              {
                "name": "20060302-01-P",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SGI",
                  "x_transferred"
                ],
                "url": "ftp://patches.sgi.com/support/free/security/advisories/20060302-01-P"
              },
              {
                "name": "20060322 Sendmail Remote Signal Handling Vulnerability",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_ISS",
                  "x_transferred"
                ],
                "url": "http://www.iss.net/threats/216.html"
              },
              {
                "name": "19466",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19466"
              },
              {
                "name": "19368",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19368"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm"
              },
              {
                "name": "Q-151",
                "tags": [
                  "third-party-advisory",
                  "government-resource",
                  "x_refsource_CIAC",
                  "x_transferred"
                ],
                "url": "http://www.ciac.org/ciac/bulletins/q-151.shtml"
              },
              {
                "name": "SSRT061133",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00629555"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://support.avaya.com/elmodocs2/security/ASA-2006-074.htm"
              },
              {
                "name": "19345",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19345"
              },
              {
                "name": "612",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SREASON",
                  "x_transferred"
                ],
                "url": "http://securityreason.com/securityalert/612"
              },
              {
                "name": "FEDORA-2006-193",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00018.html"
              },
              {
                "name": "19346",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19346"
              },
              {
                "name": "SSA:2006-081-01",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SLACKWARE",
                  "x_transferred"
                ],
                "url": "http://slackware.com/security/viewer.php?l=slackware-security\u0026y=2006\u0026m=slackware-security.619600"
              },
              {
                "name": "IY82992",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_AIXAPAR",
                  "x_transferred"
                ],
                "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY82992\u0026apar=only"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18\u0026ID=2751"
              },
              {
                "name": "GLSA-200603-21",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://www.gentoo.org/security/en/glsa/glsa-200603-21.xml"
              },
              {
                "name": "IY82994",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_AIXAPAR",
                  "x_transferred"
                ],
                "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY82994\u0026apar=only"
              },
              {
                "name": "IY82993",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_AIXAPAR",
                  "x_transferred"
                ],
                "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY82993\u0026apar=only"
              },
              {
                "name": "ADV-2006-1068",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/1068"
              },
              {
                "name": "RHSA-2006:0265",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2006-0265.html"
              },
              {
                "name": "ADV-2006-2490",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/2490"
              },
              {
                "name": "ADV-2006-1072",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/1072"
              },
              {
                "name": "FLSA:186277",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/428656/100/0/threaded"
              },
              {
                "name": "19360",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19360"
              },
              {
                "name": "19532",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19532"
              },
              {
                "name": "102324",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102324-1"
              },
              {
                "name": "19361",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19361"
              },
              {
                "name": "19676",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19676"
              },
              {
                "name": "19356",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19356"
              },
              {
                "name": "SUSE-SA:2006:017",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://www.novell.com/linux/security/advisories/2006_17_sendmail.html"
              },
              {
                "name": "24037",
                "tags": [
                  "vdb-entry",
                  "x_refsource_OSVDB",
                  "x_transferred"
                ],
                "url": "http://www.osvdb.org/24037"
              },
              {
                "name": "19349",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19349"
              },
              {
                "name": "102262",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102262-1"
              },
              {
                "name": "19394",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19394"
              },
              {
                "name": "SSRT061135",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
              },
              {
                "name": "ADV-2006-1139",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/1139"
              },
              {
                "name": "ADV-2006-1157",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/1157"
              },
              {
                "name": "19533",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19533"
              },
              {
                "name": "oval:org.mitre.oval:def:1689",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1689"
              },
              {
                "name": "NetBSD-SA2006-010",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_NETBSD",
                  "x_transferred"
                ],
                "url": "ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-010.txt.asc"
              },
              {
                "name": "17192",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/17192"
              },
              {
                "name": "RHSA-2006:0264",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2006-0264.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.sendmail.com/company/advisory/index.shtml"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2006-03-22T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-10-19T14:57:01.000Z",
            "orgId": "37e5125f-f79b-445b-8fad-9564f167944b",
            "shortName": "certcc"
          },
          "references": [
            {
              "name": "ADV-2006-1529",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/1529"
            },
            {
              "name": "HPSBTU02116",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
            },
            {
              "name": "19450",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19450"
            },
            {
              "name": "DSA-1015",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2006/dsa-1015"
            },
            {
              "name": "MDKSA-2006:058",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:058"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688"
            },
            {
              "name": "[3.8] 006: SECURITY FIX: March 25, 2006",
              "tags": [
                "vendor-advisory",
                "x_refsource_OPENBSD"
              ],
              "url": "http://www.openbsd.org/errata38.html#sendmail"
            },
            {
              "name": "VU#834865",
              "tags": [
                "third-party-advisory",
                "x_refsource_CERT-VN"
              ],
              "url": "http://www.kb.cert.org/vuls/id/834865"
            },
            {
              "name": "SCOSA-2006.24",
              "tags": [
                "vendor-advisory",
                "x_refsource_SCO"
              ],
              "url": "ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.24/SCOSA-2006.24.txt"
            },
            {
              "name": "19342",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19342"
            },
            {
              "name": "ADV-2006-1049",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/1049"
            },
            {
              "name": "19774",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19774"
            },
            {
              "name": "FreeBSD-SA-06:13",
              "tags": [
                "vendor-advisory",
                "x_refsource_FREEBSD"
              ],
              "url": "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:13.sendmail.asc"
            },
            {
              "name": "oval:org.mitre.oval:def:11074",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11074"
            },
            {
              "name": "20060401-01-U",
              "tags": [
                "vendor-advisory",
                "x_refsource_SGI"
              ],
              "url": "ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U"
            },
            {
              "name": "200494",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-66-200494-1"
            },
            {
              "name": "19404",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19404"
            },
            {
              "name": "19367",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19367"
            },
            {
              "name": "OpenPKG-SA-2006.007",
              "tags": [
                "vendor-advisory",
                "x_refsource_OPENPKG"
              ],
              "url": "http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.007-sendmail.html"
            },
            {
              "name": "ADV-2006-1051",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/1051"
            },
            {
              "name": "20060322 sendmail vuln advisories (CVE-2006-0058)",
              "tags": [
                "mailing-list",
                "x_refsource_BUGTRAQ"
              ],
              "url": "http://www.securityfocus.com/archive/1/428536/100/0/threaded"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.f-secure.com/security/fsc-2006-2.shtml"
            },
            {
              "name": "743",
              "tags": [
                "third-party-advisory",
                "x_refsource_SREASON"
              ],
              "url": "http://securityreason.com/securityalert/743"
            },
            {
              "name": "1015801",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://securitytracker.com/id?1015801"
            },
            {
              "name": "HPSBUX02108",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00629555"
            },
            {
              "name": "19363",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19363"
            },
            {
              "name": "smtp-timeout-bo(24584)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/24584"
            },
            {
              "name": "TA06-081A",
              "tags": [
                "third-party-advisory",
                "x_refsource_CERT"
              ],
              "url": "http://www.us-cert.gov/cas/techalerts/TA06-081A.html"
            },
            {
              "name": "20723",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20723"
            },
            {
              "name": "20243",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20243"
            },
            {
              "name": "19407",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19407"
            },
            {
              "name": "ADV-2006-2189",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/2189"
            },
            {
              "name": "FEDORA-2006-194",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00017.html"
            },
            {
              "name": "20060302-01-P",
              "tags": [
                "vendor-advisory",
                "x_refsource_SGI"
              ],
              "url": "ftp://patches.sgi.com/support/free/security/advisories/20060302-01-P"
            },
            {
              "name": "20060322 Sendmail Remote Signal Handling Vulnerability",
              "tags": [
                "third-party-advisory",
                "x_refsource_ISS"
              ],
              "url": "http://www.iss.net/threats/216.html"
            },
            {
              "name": "19466",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19466"
            },
            {
              "name": "19368",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19368"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm"
            },
            {
              "name": "Q-151",
              "tags": [
                "third-party-advisory",
                "government-resource",
                "x_refsource_CIAC"
              ],
              "url": "http://www.ciac.org/ciac/bulletins/q-151.shtml"
            },
            {
              "name": "SSRT061133",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00629555"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://support.avaya.com/elmodocs2/security/ASA-2006-074.htm"
            },
            {
              "name": "19345",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19345"
            },
            {
              "name": "612",
              "tags": [
                "third-party-advisory",
                "x_refsource_SREASON"
              ],
              "url": "http://securityreason.com/securityalert/612"
            },
            {
              "name": "FEDORA-2006-193",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00018.html"
            },
            {
              "name": "19346",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19346"
            },
            {
              "name": "SSA:2006-081-01",
              "tags": [
                "vendor-advisory",
                "x_refsource_SLACKWARE"
              ],
              "url": "http://slackware.com/security/viewer.php?l=slackware-security\u0026y=2006\u0026m=slackware-security.619600"
            },
            {
              "name": "IY82992",
              "tags": [
                "vendor-advisory",
                "x_refsource_AIXAPAR"
              ],
              "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY82992\u0026apar=only"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18\u0026ID=2751"
            },
            {
              "name": "GLSA-200603-21",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://www.gentoo.org/security/en/glsa/glsa-200603-21.xml"
            },
            {
              "name": "IY82994",
              "tags": [
                "vendor-advisory",
                "x_refsource_AIXAPAR"
              ],
              "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY82994\u0026apar=only"
            },
            {
              "name": "IY82993",
              "tags": [
                "vendor-advisory",
                "x_refsource_AIXAPAR"
              ],
              "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY82993\u0026apar=only"
            },
            {
              "name": "ADV-2006-1068",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/1068"
            },
            {
              "name": "RHSA-2006:0265",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2006-0265.html"
            },
            {
              "name": "ADV-2006-2490",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/2490"
            },
            {
              "name": "ADV-2006-1072",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/1072"
            },
            {
              "name": "FLSA:186277",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "http://www.securityfocus.com/archive/1/428656/100/0/threaded"
            },
            {
              "name": "19360",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19360"
            },
            {
              "name": "19532",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19532"
            },
            {
              "name": "102324",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102324-1"
            },
            {
              "name": "19361",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19361"
            },
            {
              "name": "19676",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19676"
            },
            {
              "name": "19356",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19356"
            },
            {
              "name": "SUSE-SA:2006:017",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://www.novell.com/linux/security/advisories/2006_17_sendmail.html"
            },
            {
              "name": "24037",
              "tags": [
                "vdb-entry",
                "x_refsource_OSVDB"
              ],
              "url": "http://www.osvdb.org/24037"
            },
            {
              "name": "19349",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19349"
            },
            {
              "name": "102262",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102262-1"
            },
            {
              "name": "19394",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19394"
            },
            {
              "name": "SSRT061135",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
            },
            {
              "name": "ADV-2006-1139",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/1139"
            },
            {
              "name": "ADV-2006-1157",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/1157"
            },
            {
              "name": "19533",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19533"
            },
            {
              "name": "oval:org.mitre.oval:def:1689",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1689"
            },
            {
              "name": "NetBSD-SA2006-010",
              "tags": [
                "vendor-advisory",
                "x_refsource_NETBSD"
              ],
              "url": "ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-010.txt.asc"
            },
            {
              "name": "17192",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/17192"
            },
            {
              "name": "RHSA-2006:0264",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2006-0264.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.sendmail.com/company/advisory/index.shtml"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cert@cert.org",
              "ID": "CVE-2006-0058",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "ADV-2006-1529",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/1529"
                },
                {
                  "name": "HPSBTU02116",
                  "refsource": "HP",
                  "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
                },
                {
                  "name": "19450",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19450"
                },
                {
                  "name": "DSA-1015",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2006/dsa-1015"
                },
                {
                  "name": "MDKSA-2006:058",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:058"
                },
                {
                  "name": "http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688",
                  "refsource": "CONFIRM",
                  "url": "http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688"
                },
                {
                  "name": "[3.8] 006: SECURITY FIX: March 25, 2006",
                  "refsource": "OPENBSD",
                  "url": "http://www.openbsd.org/errata38.html#sendmail"
                },
                {
                  "name": "VU#834865",
                  "refsource": "CERT-VN",
                  "url": "http://www.kb.cert.org/vuls/id/834865"
                },
                {
                  "name": "SCOSA-2006.24",
                  "refsource": "SCO",
                  "url": "ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.24/SCOSA-2006.24.txt"
                },
                {
                  "name": "19342",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19342"
                },
                {
                  "name": "ADV-2006-1049",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/1049"
                },
                {
                  "name": "19774",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19774"
                },
                {
                  "name": "FreeBSD-SA-06:13",
                  "refsource": "FREEBSD",
                  "url": "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:13.sendmail.asc"
                },
                {
                  "name": "oval:org.mitre.oval:def:11074",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11074"
                },
                {
                  "name": "20060401-01-U",
                  "refsource": "SGI",
                  "url": "ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U"
                },
                {
                  "name": "200494",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-66-200494-1"
                },
                {
                  "name": "19404",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19404"
                },
                {
                  "name": "19367",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19367"
                },
                {
                  "name": "OpenPKG-SA-2006.007",
                  "refsource": "OPENPKG",
                  "url": "http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.007-sendmail.html"
                },
                {
                  "name": "ADV-2006-1051",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/1051"
                },
                {
                  "name": "20060322 sendmail vuln advisories (CVE-2006-0058)",
                  "refsource": "BUGTRAQ",
                  "url": "http://www.securityfocus.com/archive/1/428536/100/0/threaded"
                },
                {
                  "name": "http://www.f-secure.com/security/fsc-2006-2.shtml",
                  "refsource": "CONFIRM",
                  "url": "http://www.f-secure.com/security/fsc-2006-2.shtml"
                },
                {
                  "name": "743",
                  "refsource": "SREASON",
                  "url": "http://securityreason.com/securityalert/743"
                },
                {
                  "name": "1015801",
                  "refsource": "SECTRACK",
                  "url": "http://securitytracker.com/id?1015801"
                },
                {
                  "name": "HPSBUX02108",
                  "refsource": "HP",
                  "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00629555"
                },
                {
                  "name": "19363",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19363"
                },
                {
                  "name": "smtp-timeout-bo(24584)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/24584"
                },
                {
                  "name": "TA06-081A",
                  "refsource": "CERT",
                  "url": "http://www.us-cert.gov/cas/techalerts/TA06-081A.html"
                },
                {
                  "name": "20723",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20723"
                },
                {
                  "name": "20243",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20243"
                },
                {
                  "name": "19407",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19407"
                },
                {
                  "name": "ADV-2006-2189",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/2189"
                },
                {
                  "name": "FEDORA-2006-194",
                  "refsource": "FEDORA",
                  "url": "http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00017.html"
                },
                {
                  "name": "20060302-01-P",
                  "refsource": "SGI",
                  "url": "ftp://patches.sgi.com/support/free/security/advisories/20060302-01-P"
                },
                {
                  "name": "20060322 Sendmail Remote Signal Handling Vulnerability",
                  "refsource": "ISS",
                  "url": "http://www.iss.net/threats/216.html"
                },
                {
                  "name": "19466",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19466"
                },
                {
                  "name": "19368",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19368"
                },
                {
                  "name": "http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm",
                  "refsource": "CONFIRM",
                  "url": "http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm"
                },
                {
                  "name": "Q-151",
                  "refsource": "CIAC",
                  "url": "http://www.ciac.org/ciac/bulletins/q-151.shtml"
                },
                {
                  "name": "SSRT061133",
                  "refsource": "HP",
                  "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00629555"
                },
                {
                  "name": "http://support.avaya.com/elmodocs2/security/ASA-2006-074.htm",
                  "refsource": "CONFIRM",
                  "url": "http://support.avaya.com/elmodocs2/security/ASA-2006-074.htm"
                },
                {
                  "name": "19345",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19345"
                },
                {
                  "name": "612",
                  "refsource": "SREASON",
                  "url": "http://securityreason.com/securityalert/612"
                },
                {
                  "name": "FEDORA-2006-193",
                  "refsource": "FEDORA",
                  "url": "http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00018.html"
                },
                {
                  "name": "19346",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19346"
                },
                {
                  "name": "SSA:2006-081-01",
                  "refsource": "SLACKWARE",
                  "url": "http://slackware.com/security/viewer.php?l=slackware-security\u0026y=2006\u0026m=slackware-security.619600"
                },
                {
                  "name": "IY82992",
                  "refsource": "AIXAPAR",
                  "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY82992\u0026apar=only"
                },
                {
                  "name": "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18\u0026ID=2751",
                  "refsource": "CONFIRM",
                  "url": "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18\u0026ID=2751"
                },
                {
                  "name": "GLSA-200603-21",
                  "refsource": "GENTOO",
                  "url": "http://www.gentoo.org/security/en/glsa/glsa-200603-21.xml"
                },
                {
                  "name": "IY82994",
                  "refsource": "AIXAPAR",
                  "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY82994\u0026apar=only"
                },
                {
                  "name": "IY82993",
                  "refsource": "AIXAPAR",
                  "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY82993\u0026apar=only"
                },
                {
                  "name": "ADV-2006-1068",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/1068"
                },
                {
                  "name": "RHSA-2006:0265",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2006-0265.html"
                },
                {
                  "name": "ADV-2006-2490",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/2490"
                },
                {
                  "name": "ADV-2006-1072",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/1072"
                },
                {
                  "name": "FLSA:186277",
                  "refsource": "FEDORA",
                  "url": "http://www.securityfocus.com/archive/1/428656/100/0/threaded"
                },
                {
                  "name": "19360",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19360"
                },
                {
                  "name": "19532",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19532"
                },
                {
                  "name": "102324",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102324-1"
                },
                {
                  "name": "19361",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19361"
                },
                {
                  "name": "19676",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19676"
                },
                {
                  "name": "19356",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19356"
                },
                {
                  "name": "SUSE-SA:2006:017",
                  "refsource": "SUSE",
                  "url": "http://www.novell.com/linux/security/advisories/2006_17_sendmail.html"
                },
                {
                  "name": "24037",
                  "refsource": "OSVDB",
                  "url": "http://www.osvdb.org/24037"
                },
                {
                  "name": "19349",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19349"
                },
                {
                  "name": "102262",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102262-1"
                },
                {
                  "name": "19394",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19394"
                },
                {
                  "name": "SSRT061135",
                  "refsource": "HP",
                  "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
                },
                {
                  "name": "ADV-2006-1139",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/1139"
                },
                {
                  "name": "ADV-2006-1157",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/1157"
                },
                {
                  "name": "19533",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19533"
                },
                {
                  "name": "oval:org.mitre.oval:def:1689",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1689"
                },
                {
                  "name": "NetBSD-SA2006-010",
                  "refsource": "NETBSD",
                  "url": "ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-010.txt.asc"
                },
                {
                  "name": "17192",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/17192"
                },
                {
                  "name": "RHSA-2006:0264",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2006-0264.html"
                },
                {
                  "name": "http://www.sendmail.com/company/advisory/index.shtml",
                  "refsource": "CONFIRM",
                  "url": "http://www.sendmail.com/company/advisory/index.shtml"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "37e5125f-f79b-445b-8fad-9564f167944b",
        "assignerShortName": "certcc",
        "cveId": "CVE-2006-0058",
        "datePublished": "2006-03-22T20:00:00.000Z",
        "dateReserved": "2006-01-01T00:00:00.000Z",
        "dateUpdated": "2024-08-07T16:18:20.809Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2005-2070 (GCVE-0-2005-2070)

    Vulnerability from nvd – Published: 2005-06-29 04:00 – Updated: 2024-08-07 22:15
    VLAI
    Summary
    The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a denial of service by keeping an open connection, which prevents ClamAV from reloading.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.novell.com/linux/security/advisories/2… vendor-advisoryx_refsource_SUSE
    http://seclists.org/lists/bugtraq/2005/Jun/0197.html mailing-listx_refsource_BUGTRAQ
    http://www.debian.org/security/2005/dsa-737 vendor-advisoryx_refsource_DEBIAN
    http://www.securityfocus.com/bid/14047 vdb-entryx_refsource_BID
    Date Public
    2005-06-23 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T22:15:37.380Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "SUSE-SA:2005:038",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://www.novell.com/linux/security/advisories/2005_38_clamav.html"
              },
              {
                "name": "20050623 long sendmail timeouts let attacker prevent milter quiesce",
                "tags": [
                  "mailing-list",
                  "x_refsource_BUGTRAQ",
                  "x_transferred"
                ],
                "url": "http://seclists.org/lists/bugtraq/2005/Jun/0197.html"
              },
              {
                "name": "DSA-737",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2005/dsa-737"
              },
              {
                "name": "14047",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/14047"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2005-06-23T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a denial of service by keeping an open connection, which prevents ClamAV from reloading."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2005-07-07T09:00:00.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "SUSE-SA:2005:038",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://www.novell.com/linux/security/advisories/2005_38_clamav.html"
            },
            {
              "name": "20050623 long sendmail timeouts let attacker prevent milter quiesce",
              "tags": [
                "mailing-list",
                "x_refsource_BUGTRAQ"
              ],
              "url": "http://seclists.org/lists/bugtraq/2005/Jun/0197.html"
            },
            {
              "name": "DSA-737",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2005/dsa-737"
            },
            {
              "name": "14047",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/14047"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2005-2070",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a denial of service by keeping an open connection, which prevents ClamAV from reloading."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "SUSE-SA:2005:038",
                  "refsource": "SUSE",
                  "url": "http://www.novell.com/linux/security/advisories/2005_38_clamav.html"
                },
                {
                  "name": "20050623 long sendmail timeouts let attacker prevent milter quiesce",
                  "refsource": "BUGTRAQ",
                  "url": "http://seclists.org/lists/bugtraq/2005/Jun/0197.html"
                },
                {
                  "name": "DSA-737",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2005/dsa-737"
                },
                {
                  "name": "14047",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/14047"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2005-2070",
        "datePublished": "2005-06-29T04:00:00.000Z",
        "dateReserved": "2005-06-29T00:00:00.000Z",
        "dateUpdated": "2024-08-07T22:15:37.380Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-51765 (GCVE-0-2023-51765)

    Vulnerability from cvelistv5 – Published: 2023-12-24 00:00 – Updated: 2024-08-02 22:48
    VLAI
    Summary
    sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports <LF>.<CR><LF> but some other popular e-mail servers do not. This is resolved in 8.18 and later versions with 'o' in srv_features.
    Severity
    No CVSS data available.
    CWE
    • n/a
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T22:48:11.197Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.openwall.com/lists/oss-security/2023/12/22/7"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.openwall.com/lists/oss-security/2023/12/21/7"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/freebsd/freebsd-src/commit/5dd76dd0cc19450133aa379ce0ce4a68ae07fb39#diff-afdf514b32ac88004952c11660c57bc96c3d8b2234007c1cbd8d7ed7fd7935cc"
              },
              {
                "name": "[oss-security] 20231224 Re: Re: New SMTP smuggling attack",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2023/12/24/1"
              },
              {
                "name": "[oss-security] 20231225 Re: Re: New SMTP smuggling attack",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2023/12/25/1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://bugzilla.suse.com/show_bug.cgi?id=1218351"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2255869"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/security/cve/CVE-2023-51765"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11782.html"
              },
              {
                "name": "[oss-security] 20231226 Re: New SMTP smuggling attack",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2023/12/26/5"
              },
              {
                "name": "[oss-security] 20231229 Re: Re: New SMTP smuggling attack",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2023/12/29/5"
              },
              {
                "name": "[oss-security] 20231230 Re: Re: New SMTP smuggling attack",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2023/12/30/3"
              },
              {
                "name": "[oss-security] 20231230 Re: Re: New SMTP smuggling attack",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2023/12/30/1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.youtube.com/watch?v=V8KPV96g1To"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lwn.net/Articles/956533/"
              },
              {
                "name": "[debian-lts-announce] 20240615 [SECURITY] [DLA 3829-1] sendmail security update",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00004.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports \u003cLF\u003e.\u003cCR\u003e\u003cLF\u003e but some other popular e-mail servers do not. This is resolved in 8.18 and later versions with \u0027o\u0027 in srv_features."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-15T09:05:58.617Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/"
            },
            {
              "url": "https://www.openwall.com/lists/oss-security/2023/12/22/7"
            },
            {
              "url": "https://www.openwall.com/lists/oss-security/2023/12/21/7"
            },
            {
              "url": "https://github.com/freebsd/freebsd-src/commit/5dd76dd0cc19450133aa379ce0ce4a68ae07fb39#diff-afdf514b32ac88004952c11660c57bc96c3d8b2234007c1cbd8d7ed7fd7935cc"
            },
            {
              "name": "[oss-security] 20231224 Re: Re: New SMTP smuggling attack",
              "tags": [
                "mailing-list"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2023/12/24/1"
            },
            {
              "name": "[oss-security] 20231225 Re: Re: New SMTP smuggling attack",
              "tags": [
                "mailing-list"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2023/12/25/1"
            },
            {
              "url": "https://bugzilla.suse.com/show_bug.cgi?id=1218351"
            },
            {
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2255869"
            },
            {
              "url": "https://access.redhat.com/security/cve/CVE-2023-51765"
            },
            {
              "url": "https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11782.html"
            },
            {
              "name": "[oss-security] 20231226 Re: New SMTP smuggling attack",
              "tags": [
                "mailing-list"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2023/12/26/5"
            },
            {
              "name": "[oss-security] 20231229 Re: Re: New SMTP smuggling attack",
              "tags": [
                "mailing-list"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2023/12/29/5"
            },
            {
              "name": "[oss-security] 20231230 Re: Re: New SMTP smuggling attack",
              "tags": [
                "mailing-list"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2023/12/30/3"
            },
            {
              "name": "[oss-security] 20231230 Re: Re: New SMTP smuggling attack",
              "tags": [
                "mailing-list"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2023/12/30/1"
            },
            {
              "url": "https://www.youtube.com/watch?v=V8KPV96g1To"
            },
            {
              "url": "https://lwn.net/Articles/956533/"
            },
            {
              "name": "[debian-lts-announce] 20240615 [SECURITY] [DLA 3829-1] sendmail security update",
              "tags": [
                "mailing-list"
              ],
              "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00004.html"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2023-51765",
        "datePublished": "2023-12-24T00:00:00.000Z",
        "dateReserved": "2023-12-24T00:00:00.000Z",
        "dateUpdated": "2024-08-02T22:48:11.197Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-3618 (GCVE-0-2021-3618)

    Vulnerability from cvelistv5 – Published: 2022-03-23 00:00 – Updated: 2024-08-03 17:01
    VLAI
    Summary
    ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
    Severity
    No CVSS data available.
    CWE
    Impacted products
    Vendor Product Version
    n/a ALPACA Affected: vsftpd 3.0.4, nginx 1.21.0, sendmail 8.17
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T17:01:07.459Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1975623"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://alpaca-attack.com/"
              },
              {
                "name": "[debian-lts-announce] 20221122 [SECURITY] [DLA 3203-1] nginx security update",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00031.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "ALPACA",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "vsftpd 3.0.4, nginx 1.21.0, sendmail 8.17"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim\u0027s traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-295",
                  "description": "CWE-295",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-11-23T00:00:00.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1975623"
            },
            {
              "url": "https://alpaca-attack.com/"
            },
            {
              "name": "[debian-lts-announce] 20221122 [SECURITY] [DLA 3203-1] nginx security update",
              "tags": [
                "mailing-list"
              ],
              "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00031.html"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2021-3618",
        "datePublished": "2022-03-23T00:00:00.000Z",
        "dateReserved": "2021-06-24T00:00:00.000Z",
        "dateUpdated": "2024-08-03T17:01:07.459Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2014-3956 (GCVE-0-2014-3956)

    Vulnerability from cvelistv5 – Published: 2014-06-04 10:00 – Updated: 2024-08-06 10:57
    VLAI
    Summary
    The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Date Public
    2014-05-21 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T10:57:18.265Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05216368"
              },
              {
                "name": "58628",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/58628"
              },
              {
                "name": "FreeBSD-SA-14:11",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FREEBSD",
                  "x_transferred"
                ],
                "url": "http://www.freebsd.org/security/advisories/FreeBSD-SA-14%3A11.sendmail.asc"
              },
              {
                "name": "MDVSA-2015:128",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2015:128"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://packetstormsecurity.com/files/126975/Slackware-Security-Advisory-sendmail-Updates.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "ftp://ftp.sendmail.org/pub/sendmail/RELEASE_NOTES"
              },
              {
                "name": "GLSA-201412-32",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://security.gentoo.org/glsa/glsa-201412-32.xml"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.sendmail.com/sm/open_source/download/8.14.9/"
              },
              {
                "name": "openSUSE-SU-2014:0804",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-updates/2014-06/msg00032.html"
              },
              {
                "name": "MDVSA-2014:147",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2014:147"
              },
              {
                "name": "FEDORA-2014-7093",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134349.html"
              },
              {
                "name": "openSUSE-SU-2014:0805",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-updates/2014-06/msg00033.html"
              },
              {
                "name": "57455",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/57455"
              },
              {
                "name": "67791",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/67791"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://advisories.mageia.org/MGASA-2014-0270.html"
              },
              {
                "name": "SSA:2014-156-04",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SLACKWARE",
                  "x_transferred"
                ],
                "url": "http://www.slackware.com/security/viewer.php?l=slackware-security\u0026y=2014\u0026m=slackware-security.728644"
              },
              {
                "name": "1030331",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id/1030331"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2014-05-21T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-12-28T19:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05216368"
            },
            {
              "name": "58628",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/58628"
            },
            {
              "name": "FreeBSD-SA-14:11",
              "tags": [
                "vendor-advisory",
                "x_refsource_FREEBSD"
              ],
              "url": "http://www.freebsd.org/security/advisories/FreeBSD-SA-14%3A11.sendmail.asc"
            },
            {
              "name": "MDVSA-2015:128",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2015:128"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://packetstormsecurity.com/files/126975/Slackware-Security-Advisory-sendmail-Updates.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "ftp://ftp.sendmail.org/pub/sendmail/RELEASE_NOTES"
            },
            {
              "name": "GLSA-201412-32",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://security.gentoo.org/glsa/glsa-201412-32.xml"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.sendmail.com/sm/open_source/download/8.14.9/"
            },
            {
              "name": "openSUSE-SU-2014:0804",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-updates/2014-06/msg00032.html"
            },
            {
              "name": "MDVSA-2014:147",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2014:147"
            },
            {
              "name": "FEDORA-2014-7093",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134349.html"
            },
            {
              "name": "openSUSE-SU-2014:0805",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-updates/2014-06/msg00033.html"
            },
            {
              "name": "57455",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/57455"
            },
            {
              "name": "67791",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/67791"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://advisories.mageia.org/MGASA-2014-0270.html"
            },
            {
              "name": "SSA:2014-156-04",
              "tags": [
                "vendor-advisory",
                "x_refsource_SLACKWARE"
              ],
              "url": "http://www.slackware.com/security/viewer.php?l=slackware-security\u0026y=2014\u0026m=slackware-security.728644"
            },
            {
              "name": "1030331",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id/1030331"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2014-3956",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05216368",
                  "refsource": "CONFIRM",
                  "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05216368"
                },
                {
                  "name": "58628",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/58628"
                },
                {
                  "name": "FreeBSD-SA-14:11",
                  "refsource": "FREEBSD",
                  "url": "http://www.freebsd.org/security/advisories/FreeBSD-SA-14%3A11.sendmail.asc"
                },
                {
                  "name": "MDVSA-2015:128",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2015:128"
                },
                {
                  "name": "http://packetstormsecurity.com/files/126975/Slackware-Security-Advisory-sendmail-Updates.html",
                  "refsource": "MISC",
                  "url": "http://packetstormsecurity.com/files/126975/Slackware-Security-Advisory-sendmail-Updates.html"
                },
                {
                  "name": "ftp://ftp.sendmail.org/pub/sendmail/RELEASE_NOTES",
                  "refsource": "CONFIRM",
                  "url": "ftp://ftp.sendmail.org/pub/sendmail/RELEASE_NOTES"
                },
                {
                  "name": "GLSA-201412-32",
                  "refsource": "GENTOO",
                  "url": "http://security.gentoo.org/glsa/glsa-201412-32.xml"
                },
                {
                  "name": "http://www.sendmail.com/sm/open_source/download/8.14.9/",
                  "refsource": "CONFIRM",
                  "url": "http://www.sendmail.com/sm/open_source/download/8.14.9/"
                },
                {
                  "name": "openSUSE-SU-2014:0804",
                  "refsource": "SUSE",
                  "url": "http://lists.opensuse.org/opensuse-updates/2014-06/msg00032.html"
                },
                {
                  "name": "MDVSA-2014:147",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2014:147"
                },
                {
                  "name": "FEDORA-2014-7093",
                  "refsource": "FEDORA",
                  "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134349.html"
                },
                {
                  "name": "openSUSE-SU-2014:0805",
                  "refsource": "SUSE",
                  "url": "http://lists.opensuse.org/opensuse-updates/2014-06/msg00033.html"
                },
                {
                  "name": "57455",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/57455"
                },
                {
                  "name": "67791",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/67791"
                },
                {
                  "name": "http://advisories.mageia.org/MGASA-2014-0270.html",
                  "refsource": "CONFIRM",
                  "url": "http://advisories.mageia.org/MGASA-2014-0270.html"
                },
                {
                  "name": "SSA:2014-156-04",
                  "refsource": "SLACKWARE",
                  "url": "http://www.slackware.com/security/viewer.php?l=slackware-security\u0026y=2014\u0026m=slackware-security.728644"
                },
                {
                  "name": "1030331",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id/1030331"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2014-3956",
        "datePublished": "2014-06-04T10:00:00.000Z",
        "dateReserved": "2014-06-03T00:00:00.000Z",
        "dateUpdated": "2024-08-06T10:57:18.265Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2009-4565 (GCVE-0-2009-4565)

    Vulnerability from cvelistv5 – Published: 2010-01-04 21:00 – Updated: 2024-08-07 07:08
    VLAI
    Summary
    sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://secunia.com/advisories/38314 third-party-advisoryx_refsource_SECUNIA
    http://security.gentoo.org/glsa/glsa-201206-30.xml vendor-advisoryx_refsource_GENTOO
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://secunia.com/advisories/39088 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2009/3661 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/37998 third-party-advisoryx_refsource_SECUNIA
    http://www.securityfocus.com/bid/37543 vdb-entryx_refsource_BID
    http://www.vupen.com/english/advisories/2011/0415 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/43366 third-party-advisoryx_refsource_SECUNIA
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://www.sendmail.org/releases/8.14.4 x_refsource_CONFIRM
    http://marc.info/?l=bugtraq&m=126953289726317&w=2 vendor-advisoryx_refsource_HP
    http://www.vupen.com/english/advisories/2010/0719 vdb-entryx_refsource_VUPEN
    http://www.redhat.com/support/errata/RHSA-2011-02… vendor-advisoryx_refsource_REDHAT
    http://www.debian.org/security/2010/dsa-1985 vendor-advisoryx_refsource_DEBIAN
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://secunia.com/advisories/40109 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/38915 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2010/1386 vdb-entryx_refsource_VUPEN
    Date Public
    2009-12-30 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T07:08:38.091Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "38314",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/38314"
              },
              {
                "name": "GLSA-201206-30",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://security.gentoo.org/glsa/glsa-201206-30.xml"
              },
              {
                "name": "1021797",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021797.1-1"
              },
              {
                "name": "39088",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/39088"
              },
              {
                "name": "ADV-2009-3661",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2009/3661"
              },
              {
                "name": "37998",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/37998"
              },
              {
                "name": "37543",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/37543"
              },
              {
                "name": "ADV-2011-0415",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2011/0415"
              },
              {
                "name": "43366",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/43366"
              },
              {
                "name": "SUSE-SR:2010:006",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html"
              },
              {
                "name": "oval:org.mitre.oval:def:10255",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10255"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.sendmail.org/releases/8.14.4"
              },
              {
                "name": "HPSBUX02508",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://marc.info/?l=bugtraq\u0026m=126953289726317\u0026w=2"
              },
              {
                "name": "ADV-2010-0719",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2010/0719"
              },
              {
                "name": "RHSA-2011:0262",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2011-0262.html"
              },
              {
                "name": "DSA-1985",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2010/dsa-1985"
              },
              {
                "name": "oval:org.mitre.oval:def:11822",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11822"
              },
              {
                "name": "SSRT100007",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://marc.info/?l=bugtraq\u0026m=126953289726317\u0026w=2"
              },
              {
                "name": "40109",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/40109"
              },
              {
                "name": "38915",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/38915"
              },
              {
                "name": "ADV-2010-1386",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2010/1386"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2009-12-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "sendmail before 8.14.4 does not properly handle a \u0027\\0\u0027 character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-09-18T12:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "38314",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/38314"
            },
            {
              "name": "GLSA-201206-30",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://security.gentoo.org/glsa/glsa-201206-30.xml"
            },
            {
              "name": "1021797",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021797.1-1"
            },
            {
              "name": "39088",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/39088"
            },
            {
              "name": "ADV-2009-3661",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2009/3661"
            },
            {
              "name": "37998",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/37998"
            },
            {
              "name": "37543",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/37543"
            },
            {
              "name": "ADV-2011-0415",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2011/0415"
            },
            {
              "name": "43366",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/43366"
            },
            {
              "name": "SUSE-SR:2010:006",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html"
            },
            {
              "name": "oval:org.mitre.oval:def:10255",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10255"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.sendmail.org/releases/8.14.4"
            },
            {
              "name": "HPSBUX02508",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://marc.info/?l=bugtraq\u0026m=126953289726317\u0026w=2"
            },
            {
              "name": "ADV-2010-0719",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2010/0719"
            },
            {
              "name": "RHSA-2011:0262",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2011-0262.html"
            },
            {
              "name": "DSA-1985",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2010/dsa-1985"
            },
            {
              "name": "oval:org.mitre.oval:def:11822",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11822"
            },
            {
              "name": "SSRT100007",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://marc.info/?l=bugtraq\u0026m=126953289726317\u0026w=2"
            },
            {
              "name": "40109",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/40109"
            },
            {
              "name": "38915",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/38915"
            },
            {
              "name": "ADV-2010-1386",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2010/1386"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2009-4565",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "sendmail before 8.14.4 does not properly handle a \u0027\\0\u0027 character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "38314",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/38314"
                },
                {
                  "name": "GLSA-201206-30",
                  "refsource": "GENTOO",
                  "url": "http://security.gentoo.org/glsa/glsa-201206-30.xml"
                },
                {
                  "name": "1021797",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021797.1-1"
                },
                {
                  "name": "39088",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/39088"
                },
                {
                  "name": "ADV-2009-3661",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2009/3661"
                },
                {
                  "name": "37998",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/37998"
                },
                {
                  "name": "37543",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/37543"
                },
                {
                  "name": "ADV-2011-0415",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2011/0415"
                },
                {
                  "name": "43366",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/43366"
                },
                {
                  "name": "SUSE-SR:2010:006",
                  "refsource": "SUSE",
                  "url": "http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html"
                },
                {
                  "name": "oval:org.mitre.oval:def:10255",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10255"
                },
                {
                  "name": "http://www.sendmail.org/releases/8.14.4",
                  "refsource": "CONFIRM",
                  "url": "http://www.sendmail.org/releases/8.14.4"
                },
                {
                  "name": "HPSBUX02508",
                  "refsource": "HP",
                  "url": "http://marc.info/?l=bugtraq\u0026m=126953289726317\u0026w=2"
                },
                {
                  "name": "ADV-2010-0719",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2010/0719"
                },
                {
                  "name": "RHSA-2011:0262",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2011-0262.html"
                },
                {
                  "name": "DSA-1985",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2010/dsa-1985"
                },
                {
                  "name": "oval:org.mitre.oval:def:11822",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11822"
                },
                {
                  "name": "SSRT100007",
                  "refsource": "HP",
                  "url": "http://marc.info/?l=bugtraq\u0026m=126953289726317\u0026w=2"
                },
                {
                  "name": "40109",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/40109"
                },
                {
                  "name": "38915",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/38915"
                },
                {
                  "name": "ADV-2010-1386",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2010/1386"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2009-4565",
        "datePublished": "2010-01-04T21:00:00.000Z",
        "dateReserved": "2010-01-04T00:00:00.000Z",
        "dateUpdated": "2024-08-07T07:08:38.091Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2009-1490 (GCVE-0-2009-1490)

    Vulnerability from cvelistv5 – Published: 2009-05-05 19:00 – Updated: 2024-08-07 05:13
    VLAI
    Summary
    Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Date Public
    2009-04-27 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T05:13:25.560Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.sendmail.org/releases/8.13.2"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://www.nmrc.org/~thegnome/blog/apr09/"
              },
              {
                "name": "sendmail-xheader-bo(50355)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/50355"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2009-04-27T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-08-16T14:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.sendmail.org/releases/8.13.2"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://www.nmrc.org/~thegnome/blog/apr09/"
            },
            {
              "name": "sendmail-xheader-bo(50355)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/50355"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2009-1490",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "http://www.sendmail.org/releases/8.13.2",
                  "refsource": "CONFIRM",
                  "url": "http://www.sendmail.org/releases/8.13.2"
                },
                {
                  "name": "http://www.nmrc.org/~thegnome/blog/apr09/",
                  "refsource": "MISC",
                  "url": "http://www.nmrc.org/~thegnome/blog/apr09/"
                },
                {
                  "name": "sendmail-xheader-bo(50355)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/50355"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2009-1490",
        "datePublished": "2009-05-05T19:00:00.000Z",
        "dateReserved": "2009-04-30T00:00:00.000Z",
        "dateUpdated": "2024-08-07T05:13:25.560Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2002-2423 (GCVE-0-2002-2423)

    Vulnerability from cvelistv5 – Published: 2007-11-01 17:00 – Updated: 2024-09-16 17:17
    VLAI
    Summary
    Sendmail 8.12.0 through 8.12.6 truncates log messages longer than 100 characters, which allows remote attackers to prevent the IP address from being logged via a long IDENT response.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.securityfocus.com/bid/5770 vdb-entryx_refsource_BID
    http://archive.cert.uni-stuttgart.de/bugtraq/2002… mailing-listx_refsource_BUGTRAQ
    http://www.iss.net/security_center/static/10153.php vdb-entryx_refsource_XF
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-08T04:06:53.908Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "5770",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/5770"
              },
              {
                "name": "20020921 Sendmail logging and short string precision allows anonymous commands/relay",
                "tags": [
                  "mailing-list",
                  "x_refsource_BUGTRAQ",
                  "x_transferred"
                ],
                "url": "http://archive.cert.uni-stuttgart.de/bugtraq/2002/09/msg00267.html"
              },
              {
                "name": "sendmail-ident-logging-bypass(10153)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "http://www.iss.net/security_center/static/10153.php"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Sendmail 8.12.0 through 8.12.6 truncates log messages longer than 100 characters, which allows remote attackers to prevent the IP address from being logged via a long IDENT response."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2007-11-01T17:00:00.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "5770",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/5770"
            },
            {
              "name": "20020921 Sendmail logging and short string precision allows anonymous commands/relay",
              "tags": [
                "mailing-list",
                "x_refsource_BUGTRAQ"
              ],
              "url": "http://archive.cert.uni-stuttgart.de/bugtraq/2002/09/msg00267.html"
            },
            {
              "name": "sendmail-ident-logging-bypass(10153)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "http://www.iss.net/security_center/static/10153.php"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2002-2423",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Sendmail 8.12.0 through 8.12.6 truncates log messages longer than 100 characters, which allows remote attackers to prevent the IP address from being logged via a long IDENT response."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "5770",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/5770"
                },
                {
                  "name": "20020921 Sendmail logging and short string precision allows anonymous commands/relay",
                  "refsource": "BUGTRAQ",
                  "url": "http://archive.cert.uni-stuttgart.de/bugtraq/2002/09/msg00267.html"
                },
                {
                  "name": "sendmail-ident-logging-bypass(10153)",
                  "refsource": "XF",
                  "url": "http://www.iss.net/security_center/static/10153.php"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2002-2423",
        "datePublished": "2007-11-01T17:00:00.000Z",
        "dateReserved": "2007-11-01T00:00:00.000Z",
        "dateUpdated": "2024-09-16T17:17:37.413Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2002-2261 (GCVE-0-2002-2261)

    Vulnerability from cvelistv5 – Published: 2007-10-18 10:00 – Updated: 2024-08-08 03:59
    VLAI
    Summary
    Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the 'check_relay' function by spoofing a blank DNS hostname.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://www.sendmail.org/8.12.7.html x_refsource_CONFIRM
    http://www.vupen.com/english/advisories/2009/3539 vdb-entryx_refsource_VUPEN
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://securitytracker.com/id?1005748 vdb-entryx_refsource_SECTRACK
    ftp://patches.sgi.com/support/free/security/advis… vendor-advisoryx_refsource_SGI
    http://www.securityfocus.com/bid/6548 vdb-entryx_refsource_BID
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    http://secunia.com/advisories/7826 third-party-advisoryx_refsource_SECUNIA
    Date Public
    2002-12-03 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-08T03:59:11.838Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "oval:org.mitre.oval:def:6892",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6892"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.sendmail.org/8.12.7.html"
              },
              {
                "name": "ADV-2009-3539",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2009/3539"
              },
              {
                "name": "oval:org.mitre.oval:def:8512",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8512"
              },
              {
                "name": "1005748",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://securitytracker.com/id?1005748"
              },
              {
                "name": "20030101-01-P",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SGI",
                  "x_transferred"
                ],
                "url": "ftp://patches.sgi.com/support/free/security/advisories/20030101-01-P"
              },
              {
                "name": "6548",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/6548"
              },
              {
                "name": "sendmail-check-relay-bypass(10775)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/10775"
              },
              {
                "name": "7826",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/7826"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2002-12-03T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the \u0027check_relay\u0027 function by spoofing a blank DNS hostname."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-10-10T00:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "oval:org.mitre.oval:def:6892",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6892"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.sendmail.org/8.12.7.html"
            },
            {
              "name": "ADV-2009-3539",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2009/3539"
            },
            {
              "name": "oval:org.mitre.oval:def:8512",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8512"
            },
            {
              "name": "1005748",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://securitytracker.com/id?1005748"
            },
            {
              "name": "20030101-01-P",
              "tags": [
                "vendor-advisory",
                "x_refsource_SGI"
              ],
              "url": "ftp://patches.sgi.com/support/free/security/advisories/20030101-01-P"
            },
            {
              "name": "6548",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/6548"
            },
            {
              "name": "sendmail-check-relay-bypass(10775)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/10775"
            },
            {
              "name": "7826",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/7826"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2002-2261",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the \u0027check_relay\u0027 function by spoofing a blank DNS hostname."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "oval:org.mitre.oval:def:6892",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6892"
                },
                {
                  "name": "http://www.sendmail.org/8.12.7.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.sendmail.org/8.12.7.html"
                },
                {
                  "name": "ADV-2009-3539",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2009/3539"
                },
                {
                  "name": "oval:org.mitre.oval:def:8512",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8512"
                },
                {
                  "name": "1005748",
                  "refsource": "SECTRACK",
                  "url": "http://securitytracker.com/id?1005748"
                },
                {
                  "name": "20030101-01-P",
                  "refsource": "SGI",
                  "url": "ftp://patches.sgi.com/support/free/security/advisories/20030101-01-P"
                },
                {
                  "name": "6548",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/6548"
                },
                {
                  "name": "sendmail-check-relay-bypass(10775)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/10775"
                },
                {
                  "name": "7826",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/7826"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2002-2261",
        "datePublished": "2007-10-18T10:00:00.000Z",
        "dateReserved": "2007-10-17T00:00:00.000Z",
        "dateUpdated": "2024-08-08T03:59:11.838Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-1999-1592 (GCVE-0-1999-1592)

    Vulnerability from cvelistv5 – Published: 2007-07-12 17:00 – Updated: 2024-09-16 17:03
    VLAI
    Summary
    Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impact. NOTE: this might overlap CVE-1999-0129.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUN
    http://www.securityfocus.com/bid/243 vdb-entryx_refsource_BID
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T17:18:07.602Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "00159",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUN",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-22-00159-1"
              },
              {
                "name": "243",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/243"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impact.  NOTE: this might overlap CVE-1999-0129."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2007-07-12T17:00:00.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "00159",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUN"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-22-00159-1"
            },
            {
              "name": "243",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/243"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-1999-1592",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impact.  NOTE: this might overlap CVE-1999-0129."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "00159",
                  "refsource": "SUN",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-22-00159-1"
                },
                {
                  "name": "243",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/243"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-1999-1592",
        "datePublished": "2007-07-12T17:00:00.000Z",
        "dateReserved": "2007-07-12T00:00:00.000Z",
        "dateUpdated": "2024-09-16T17:03:10.002Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2007-2246 (GCVE-0-2007-2246)

    Vulnerability from cvelistv5 – Published: 2007-04-25 16:00 – Updated: 2024-08-07 13:33
    VLAI
    Summary
    Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.1; allows remote attackers to cause a denial of service via unknown attack vectors. NOTE: due to the lack of details from HP, it is not known whether this issue is a duplicate of another CVE such as CVE-2006-1173 or CVE-2006-4434.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.securitytracker.com/id?1017966 vdb-entryx_refsource_SECTRACK
    http://www.securityfocus.com/bid/23606 vdb-entryx_refsource_BID
    http://www.kb.cert.org/vuls/id/349305 third-party-advisoryx_refsource_CERT-VN
    http://secunia.com/advisories/24990 third-party-advisoryx_refsource_SECUNIA
    http://h20000.www2.hp.com/bizsupport/TechSupport/… vendor-advisoryx_refsource_HP
    http://www.vupen.com/english/advisories/2007/1504 vdb-entryx_refsource_VUPEN
    Date Public
    2007-04-16 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T13:33:28.308Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "1017966",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1017966"
              },
              {
                "name": "23606",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/23606"
              },
              {
                "name": "VU#349305",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_CERT-VN",
                  "x_transferred"
                ],
                "url": "http://www.kb.cert.org/vuls/id/349305"
              },
              {
                "name": "24990",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/24990"
              },
              {
                "name": "SSRT061243",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00841370"
              },
              {
                "name": "HPSBUX02183",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00841370"
              },
              {
                "name": "ADV-2007-1504",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2007/1504"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2007-04-16T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.1; allows remote attackers to cause a denial of service via unknown attack vectors.  NOTE: due to the lack of details from HP, it is not known whether this issue is a duplicate of another CVE such as CVE-2006-1173 or CVE-2006-4434."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2007-05-02T09:00:00.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "1017966",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1017966"
            },
            {
              "name": "23606",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/23606"
            },
            {
              "name": "VU#349305",
              "tags": [
                "third-party-advisory",
                "x_refsource_CERT-VN"
              ],
              "url": "http://www.kb.cert.org/vuls/id/349305"
            },
            {
              "name": "24990",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/24990"
            },
            {
              "name": "SSRT061243",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00841370"
            },
            {
              "name": "HPSBUX02183",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00841370"
            },
            {
              "name": "ADV-2007-1504",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2007/1504"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2007-2246",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.1; allows remote attackers to cause a denial of service via unknown attack vectors.  NOTE: due to the lack of details from HP, it is not known whether this issue is a duplicate of another CVE such as CVE-2006-1173 or CVE-2006-4434."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "1017966",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id?1017966"
                },
                {
                  "name": "23606",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/23606"
                },
                {
                  "name": "VU#349305",
                  "refsource": "CERT-VN",
                  "url": "http://www.kb.cert.org/vuls/id/349305"
                },
                {
                  "name": "24990",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/24990"
                },
                {
                  "name": "SSRT061243",
                  "refsource": "HP",
                  "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00841370"
                },
                {
                  "name": "HPSBUX02183",
                  "refsource": "HP",
                  "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00841370"
                },
                {
                  "name": "ADV-2007-1504",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2007/1504"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2007-2246",
        "datePublished": "2007-04-25T16:00:00.000Z",
        "dateReserved": "2007-04-25T00:00:00.000Z",
        "dateUpdated": "2024-08-07T13:33:28.308Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2006-7175 (GCVE-0-2006-7175)

    Vulnerability from cvelistv5 – Published: 2007-03-27 23:00 – Updated: 2024-08-07 20:57
    VLAI
    Summary
    The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryption, which could cause less secure channels to be used than desired.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Date Public
    2006-08-18 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T20:57:39.637Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=172352"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2006-08-18T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryption, which could cause less secure channels to be used than desired."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-10-03T16:21:25.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=172352"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2006-7175",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryption, which could cause less secure channels to be used than desired."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=172352",
                  "refsource": "MISC",
                  "url": "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=172352"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2006-7175",
        "datePublished": "2007-03-27T23:00:00.000Z",
        "dateReserved": "2007-03-27T00:00:00.000Z",
        "dateUpdated": "2024-08-07T20:57:39.637Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2006-7176 (GCVE-0-2006-7176)

    Vulnerability from cvelistv5 – Published: 2007-03-27 23:00 – Updated: 2024-08-07 20:57
    VLAI
    Summary
    The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not reject the "localhost.localdomain" domain name for e-mail messages that come from external hosts, which might allow remote attackers to spoof messages.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://secunia.com/advisories/25098 third-party-advisoryx_refsource_SECUNIA
    https://bugzilla.redhat.com/bugzilla/show_bug.cgi… x_refsource_MISC
    http://www.redhat.com/support/errata/RHSA-2007-02… vendor-advisoryx_refsource_REDHAT
    http://secunia.com/advisories/25743 third-party-advisoryx_refsource_SECUNIA
    http://support.avaya.com/elmodocs2/security/ASA-2… x_refsource_CONFIRM
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://www.securityfocus.com/bid/23742 vdb-entryx_refsource_BID
    Date Public
    2006-10-02 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T20:57:39.637Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "25098",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/25098"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=171838"
              },
              {
                "name": "RHSA-2007:0252",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2007-0252.html"
              },
              {
                "name": "25743",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/25743"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://support.avaya.com/elmodocs2/security/ASA-2007-248.htm"
              },
              {
                "name": "oval:org.mitre.oval:def:11499",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11499"
              },
              {
                "name": "23742",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/23742"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2006-10-02T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not reject the \"localhost.localdomain\" domain name for e-mail messages that come from external hosts, which might allow remote attackers to spoof messages."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-10-10T00:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "25098",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/25098"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=171838"
            },
            {
              "name": "RHSA-2007:0252",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2007-0252.html"
            },
            {
              "name": "25743",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/25743"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://support.avaya.com/elmodocs2/security/ASA-2007-248.htm"
            },
            {
              "name": "oval:org.mitre.oval:def:11499",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11499"
            },
            {
              "name": "23742",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/23742"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2006-7176",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not reject the \"localhost.localdomain\" domain name for e-mail messages that come from external hosts, which might allow remote attackers to spoof messages."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "25098",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/25098"
                },
                {
                  "name": "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=171838",
                  "refsource": "MISC",
                  "url": "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=171838"
                },
                {
                  "name": "RHSA-2007:0252",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2007-0252.html"
                },
                {
                  "name": "25743",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/25743"
                },
                {
                  "name": "http://support.avaya.com/elmodocs2/security/ASA-2007-248.htm",
                  "refsource": "CONFIRM",
                  "url": "http://support.avaya.com/elmodocs2/security/ASA-2007-248.htm"
                },
                {
                  "name": "oval:org.mitre.oval:def:11499",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11499"
                },
                {
                  "name": "23742",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/23742"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2006-7176",
        "datePublished": "2007-03-27T23:00:00.000Z",
        "dateReserved": "2007-03-27T00:00:00.000Z",
        "dateUpdated": "2024-08-07T20:57:39.637Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2006-4434 (GCVE-0-2006-4434)

    Vulnerability from cvelistv5 – Published: 2006-08-29 00:00 – Updated: 2024-08-07 19:06
    VLAI
    Summary
    Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected."
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.openbsd.org/errata.html#sendmail3 vendor-advisoryx_refsource_OPENBSD
    http://www.attrition.org/pipermail/vim/2006-Augus… mailing-listx_refsource_VIM
    http://securitytracker.com/id?1016753 vdb-entryx_refsource_SECTRACK
    http://secunia.com/advisories/21637 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2006/3994 vdb-entryx_refsource_VUPEN
    http://www.osvdb.org/28193 vdb-entryx_refsource_OSVDB
    http://secunia.com/advisories/21749 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/21700 third-party-advisoryx_refsource_SECUNIA
    http://www.debian.org/security/2006/dsa-1164 vendor-advisoryx_refsource_DEBIAN
    http://secunia.com/advisories/21641 third-party-advisoryx_refsource_SECUNIA
    http://www.sendmail.org/releases/8.13.8.html x_refsource_CONFIRM
    http://www.vupen.com/english/advisories/2006/3393 vdb-entryx_refsource_VUPEN
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://www.securityfocus.com/bid/19714 vdb-entryx_refsource_BID
    http://www.novell.com/linux/security/advisories/2… vendor-advisoryx_refsource_SUSE
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://secunia.com/advisories/22369 third-party-advisoryx_refsource_SECUNIA
    http://www.openbsd.org/errata38.html#sendmail3 vendor-advisoryx_refsource_OPENBSD
    http://secunia.com/advisories/21696 third-party-advisoryx_refsource_SECUNIA
    Date Public
    2006-08-09 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T19:06:07.644Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "[3.9] 20060825 005: SECURITY FIX: August 25, 2006",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_OPENBSD",
                  "x_transferred"
                ],
                "url": "http://www.openbsd.org/errata.html#sendmail3"
              },
              {
                "name": "20060829 Sendmail vendor dispute - CVE-2006-4434 (fwd)",
                "tags": [
                  "mailing-list",
                  "x_refsource_VIM",
                  "x_transferred"
                ],
                "url": "http://www.attrition.org/pipermail/vim/2006-August/000999.html"
              },
              {
                "name": "1016753",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://securitytracker.com/id?1016753"
              },
              {
                "name": "21637",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/21637"
              },
              {
                "name": "ADV-2006-3994",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/3994"
              },
              {
                "name": "28193",
                "tags": [
                  "vdb-entry",
                  "x_refsource_OSVDB",
                  "x_transferred"
                ],
                "url": "http://www.osvdb.org/28193"
              },
              {
                "name": "21749",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/21749"
              },
              {
                "name": "21700",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/21700"
              },
              {
                "name": "DSA-1164",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2006/dsa-1164"
              },
              {
                "name": "21641",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/21641"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.sendmail.org/releases/8.13.8.html"
              },
              {
                "name": "ADV-2006-3393",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/3393"
              },
              {
                "name": "MDKSA-2006:156",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:156"
              },
              {
                "name": "19714",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/19714"
              },
              {
                "name": "SUSE-SR:2006:021",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://www.novell.com/linux/security/advisories/2006_21_sr.html"
              },
              {
                "name": "102664",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102664-1"
              },
              {
                "name": "22369",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/22369"
              },
              {
                "name": "[3.8] 20060825 010: SECURITY FIX: August 25, 2006",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_OPENBSD",
                  "x_transferred"
                ],
                "url": "http://www.openbsd.org/errata38.html#sendmail3"
              },
              {
                "name": "21696",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/21696"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2006-08-09T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long \"header line\", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying \"The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected.\""
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2006-09-02T09:00:00.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "[3.9] 20060825 005: SECURITY FIX: August 25, 2006",
              "tags": [
                "vendor-advisory",
                "x_refsource_OPENBSD"
              ],
              "url": "http://www.openbsd.org/errata.html#sendmail3"
            },
            {
              "name": "20060829 Sendmail vendor dispute - CVE-2006-4434 (fwd)",
              "tags": [
                "mailing-list",
                "x_refsource_VIM"
              ],
              "url": "http://www.attrition.org/pipermail/vim/2006-August/000999.html"
            },
            {
              "name": "1016753",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://securitytracker.com/id?1016753"
            },
            {
              "name": "21637",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/21637"
            },
            {
              "name": "ADV-2006-3994",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/3994"
            },
            {
              "name": "28193",
              "tags": [
                "vdb-entry",
                "x_refsource_OSVDB"
              ],
              "url": "http://www.osvdb.org/28193"
            },
            {
              "name": "21749",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/21749"
            },
            {
              "name": "21700",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/21700"
            },
            {
              "name": "DSA-1164",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2006/dsa-1164"
            },
            {
              "name": "21641",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/21641"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.sendmail.org/releases/8.13.8.html"
            },
            {
              "name": "ADV-2006-3393",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/3393"
            },
            {
              "name": "MDKSA-2006:156",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:156"
            },
            {
              "name": "19714",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/19714"
            },
            {
              "name": "SUSE-SR:2006:021",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://www.novell.com/linux/security/advisories/2006_21_sr.html"
            },
            {
              "name": "102664",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102664-1"
            },
            {
              "name": "22369",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/22369"
            },
            {
              "name": "[3.8] 20060825 010: SECURITY FIX: August 25, 2006",
              "tags": [
                "vendor-advisory",
                "x_refsource_OPENBSD"
              ],
              "url": "http://www.openbsd.org/errata38.html#sendmail3"
            },
            {
              "name": "21696",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/21696"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2006-4434",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long \"header line\", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying \"The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected.\""
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "[3.9] 20060825 005: SECURITY FIX: August 25, 2006",
                  "refsource": "OPENBSD",
                  "url": "http://www.openbsd.org/errata.html#sendmail3"
                },
                {
                  "name": "20060829 Sendmail vendor dispute - CVE-2006-4434 (fwd)",
                  "refsource": "VIM",
                  "url": "http://www.attrition.org/pipermail/vim/2006-August/000999.html"
                },
                {
                  "name": "1016753",
                  "refsource": "SECTRACK",
                  "url": "http://securitytracker.com/id?1016753"
                },
                {
                  "name": "21637",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/21637"
                },
                {
                  "name": "ADV-2006-3994",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/3994"
                },
                {
                  "name": "28193",
                  "refsource": "OSVDB",
                  "url": "http://www.osvdb.org/28193"
                },
                {
                  "name": "21749",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/21749"
                },
                {
                  "name": "21700",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/21700"
                },
                {
                  "name": "DSA-1164",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2006/dsa-1164"
                },
                {
                  "name": "21641",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/21641"
                },
                {
                  "name": "http://www.sendmail.org/releases/8.13.8.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.sendmail.org/releases/8.13.8.html"
                },
                {
                  "name": "ADV-2006-3393",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/3393"
                },
                {
                  "name": "MDKSA-2006:156",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:156"
                },
                {
                  "name": "19714",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/19714"
                },
                {
                  "name": "SUSE-SR:2006:021",
                  "refsource": "SUSE",
                  "url": "http://www.novell.com/linux/security/advisories/2006_21_sr.html"
                },
                {
                  "name": "102664",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102664-1"
                },
                {
                  "name": "22369",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/22369"
                },
                {
                  "name": "[3.8] 20060825 010: SECURITY FIX: August 25, 2006",
                  "refsource": "OPENBSD",
                  "url": "http://www.openbsd.org/errata38.html#sendmail3"
                },
                {
                  "name": "21696",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/21696"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2006-4434",
        "datePublished": "2006-08-29T00:00:00.000Z",
        "dateReserved": "2006-08-28T00:00:00.000Z",
        "dateUpdated": "2024-08-07T19:06:07.644Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2006-1173 (GCVE-0-2006-1173)

    Vulnerability from cvelistv5 – Published: 2006-06-07 23:00 – Updated: 2024-08-07 17:03
    VLAI
    Summary
    Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www-1.ibm.com/support/search.wss?rs=0&q=IY… vendor-advisoryx_refsource_AIXAPAR
    http://itrc.hp.com/service/cki/docDisplay.do?docI… vendor-advisoryx_refsource_HP
    http://www.debian.org/security/2006/dsa-1155 vendor-advisoryx_refsource_DEBIAN
    http://www.openbsd.org/errata38.html#sendmail2 vendor-advisoryx_refsource_OPENBSD
    http://secunia.com/advisories/20684 third-party-advisoryx_refsource_SECUNIA
    http://www.securityfocus.com/archive/1/442939/100… vendor-advisoryx_refsource_HP
    http://www.vupen.com/english/advisories/2006/2388 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/20726 third-party-advisoryx_refsource_SECUNIA
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://www.vupen.com/english/advisories/2006/2351 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/21327 third-party-advisoryx_refsource_SECUNIA
    http://www.redhat.com/support/errata/RHSA-2006-05… vendor-advisoryx_refsource_REDHAT
    http://www.vupen.com/english/advisories/2006/2389 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/21647 third-party-advisoryx_refsource_SECUNIA
    http://www.fortinet.com/FortiGuardCenter/advisory… x_refsource_CONFIRM
    https://issues.rpath.com/browse/RPL-526 x_refsource_CONFIRM
    http://secunia.com/advisories/20651 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/20683 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/20650 third-party-advisoryx_refsource_SECUNIA
    http://support.avaya.com/elmodocs2/security/ASA-2… x_refsource_CONFIRM
    http://secunia.com/advisories/20782 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2006/3135 vdb-entryx_refsource_VUPEN
    http://securitytracker.com/id?1016295 vdb-entryx_refsource_SECTRACK
    http://secunia.com/advisories/20694 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/20473 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2006/2189 vdb-entryx_refsource_VUPEN
    http://www.securityfocus.com/archive/1/440744/100… mailing-listx_refsource_BUGTRAQ
    ftp://patches.sgi.com/support/free/security/advis… vendor-advisoryx_refsource_SGI
    http://www.vupen.com/english/advisories/2006/2798 vdb-entryx_refsource_VUPEN
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://www.sendmail.com/security/advisories/SA-20… x_refsource_CONFIRM
    ftp://patches.sgi.com/support/free/security/advis… vendor-advisoryx_refsource_SGI
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    http://secunia.com/advisories/20673 third-party-advisoryx_refsource_SECUNIA
    http://www.f-secure.com/security/fsc-2006-5.shtml x_refsource_CONFIRM
    http://www.securityfocus.com/archive/1/438241/100… mailing-listx_refsource_BUGTRAQ
    http://secunia.com/advisories/21612 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/20654 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2006/2390 vdb-entryx_refsource_VUPEN
    http://slackware.com/security/viewer.php?l=slackw… vendor-advisoryx_refsource_SLACKWARE
    http://www.gentoo.org/security/en/glsa/glsa-20060… vendor-advisoryx_refsource_GENTOO
    http://www.securityfocus.com/bid/18433 vdb-entryx_refsource_BID
    http://secunia.com/advisories/20675 third-party-advisoryx_refsource_SECUNIA
    http://lists.suse.com/archive/suse-security-annou… vendor-advisoryx_refsource_SUSE
    ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories… vendor-advisoryx_refsource_FREEBSD
    http://www.securityfocus.com/archive/1/437928/100… mailing-listx_refsource_BUGTRAQ
    http://www.kb.cert.org/vuls/id/146718 third-party-advisoryx_refsource_CERT-VN
    http://secunia.com/advisories/15779 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/20641 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/20679 third-party-advisoryx_refsource_SECUNIA
    http://www.osvdb.org/26197 vdb-entryx_refsource_OSVDB
    http://secunia.com/advisories/21042 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/21160 third-party-advisoryx_refsource_SECUNIA
    http://www-1.ibm.com/support/search.wss?rs=0&q=IY… vendor-advisoryx_refsource_AIXAPAR
    http://www.securityfocus.com/archive/1/438330/100… mailing-listx_refsource_BUGTRAQ
    Date Public
    2006-06-06 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T17:03:28.441Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "IY85415",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_AIXAPAR",
                  "x_transferred"
                ],
                "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY85415\u0026apar=only"
              },
              {
                "name": "HPSBTU02116",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
              },
              {
                "name": "DSA-1155",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2006/dsa-1155"
              },
              {
                "name": "[3.8] 008: SECURITY FIX: June 15, 2006",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_OPENBSD",
                  "x_transferred"
                ],
                "url": "http://www.openbsd.org/errata38.html#sendmail2"
              },
              {
                "name": "20684",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20684"
              },
              {
                "name": "HPSBUX02124",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/442939/100/0/threaded"
              },
              {
                "name": "ADV-2006-2388",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/2388"
              },
              {
                "name": "20726",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20726"
              },
              {
                "name": "oval:org.mitre.oval:def:11253",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11253"
              },
              {
                "name": "ADV-2006-2351",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/2351"
              },
              {
                "name": "21327",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/21327"
              },
              {
                "name": "RHSA-2006:0515",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2006-0515.html"
              },
              {
                "name": "ADV-2006-2389",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/2389"
              },
              {
                "name": "21647",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/21647"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-18.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://issues.rpath.com/browse/RPL-526"
              },
              {
                "name": "20651",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20651"
              },
              {
                "name": "20683",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20683"
              },
              {
                "name": "20650",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20650"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://support.avaya.com/elmodocs2/security/ASA-2006-148.htm"
              },
              {
                "name": "20782",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20782"
              },
              {
                "name": "ADV-2006-3135",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/3135"
              },
              {
                "name": "1016295",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://securitytracker.com/id?1016295"
              },
              {
                "name": "20694",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20694"
              },
              {
                "name": "20473",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20473"
              },
              {
                "name": "ADV-2006-2189",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/2189"
              },
              {
                "name": "20060721 rPSA-2006-0134-1 sendmail sendmail-cf",
                "tags": [
                  "mailing-list",
                  "x_refsource_BUGTRAQ",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/440744/100/0/threaded"
              },
              {
                "name": "20060601-01-P",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SGI",
                  "x_transferred"
                ],
                "url": "ftp://patches.sgi.com/support/free/security/advisories/20060601-01-P"
              },
              {
                "name": "ADV-2006-2798",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/2798"
              },
              {
                "name": "102460",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102460-1"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.sendmail.com/security/advisories/SA-200605-01.txt.asc"
              },
              {
                "name": "20060602-01-U",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SGI",
                  "x_transferred"
                ],
                "url": "ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc"
              },
              {
                "name": "MDKSA-2006:104",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:104"
              },
              {
                "name": "sendmail-multipart-mime-dos(27128)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27128"
              },
              {
                "name": "20673",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20673"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.f-secure.com/security/fsc-2006-5.shtml"
              },
              {
                "name": "20060621 Re: Sendmail MIME DoS vulnerability",
                "tags": [
                  "mailing-list",
                  "x_refsource_BUGTRAQ",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/438241/100/0/threaded"
              },
              {
                "name": "21612",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/21612"
              },
              {
                "name": "20654",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20654"
              },
              {
                "name": "ADV-2006-2390",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/2390"
              },
              {
                "name": "SSA:2006-166-01",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SLACKWARE",
                  "x_transferred"
                ],
                "url": "http://slackware.com/security/viewer.php?l=slackware-security\u0026y=2006\u0026m=slackware-security.631382"
              },
              {
                "name": "GLSA-200606-19",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://www.gentoo.org/security/en/glsa/glsa-200606-19.xml"
              },
              {
                "name": "18433",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/18433"
              },
              {
                "name": "20675",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20675"
              },
              {
                "name": "SUSE-SA:2006:032",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.suse.com/archive/suse-security-announce/2006-Jun/0006.html"
              },
              {
                "name": "FreeBSD-SA-06:17.sendmail",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FREEBSD",
                  "x_transferred"
                ],
                "url": "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:17.sendmail.asc"
              },
              {
                "name": "20060620 Sendmail MIME DoS vulnerability",
                "tags": [
                  "mailing-list",
                  "x_refsource_BUGTRAQ",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/437928/100/0/threaded"
              },
              {
                "name": "SSRT061159",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/442939/100/0/threaded"
              },
              {
                "name": "VU#146718",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_CERT-VN",
                  "x_transferred"
                ],
                "url": "http://www.kb.cert.org/vuls/id/146718"
              },
              {
                "name": "SSRT061135",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
              },
              {
                "name": "15779",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/15779"
              },
              {
                "name": "20641",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20641"
              },
              {
                "name": "20679",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20679"
              },
              {
                "name": "26197",
                "tags": [
                  "vdb-entry",
                  "x_refsource_OSVDB",
                  "x_transferred"
                ],
                "url": "http://www.osvdb.org/26197"
              },
              {
                "name": "21042",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/21042"
              },
              {
                "name": "21160",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/21160"
              },
              {
                "name": "IY85930",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_AIXAPAR",
                  "x_transferred"
                ],
                "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY85930\u0026apar=only"
              },
              {
                "name": "20060624 Re: Sendmail MIME DoS vulnerability",
                "tags": [
                  "mailing-list",
                  "x_refsource_BUGTRAQ",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/438330/100/0/threaded"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2006-06-06T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-10-18T14:57:01.000Z",
            "orgId": "37e5125f-f79b-445b-8fad-9564f167944b",
            "shortName": "certcc"
          },
          "references": [
            {
              "name": "IY85415",
              "tags": [
                "vendor-advisory",
                "x_refsource_AIXAPAR"
              ],
              "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY85415\u0026apar=only"
            },
            {
              "name": "HPSBTU02116",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
            },
            {
              "name": "DSA-1155",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2006/dsa-1155"
            },
            {
              "name": "[3.8] 008: SECURITY FIX: June 15, 2006",
              "tags": [
                "vendor-advisory",
                "x_refsource_OPENBSD"
              ],
              "url": "http://www.openbsd.org/errata38.html#sendmail2"
            },
            {
              "name": "20684",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20684"
            },
            {
              "name": "HPSBUX02124",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://www.securityfocus.com/archive/1/442939/100/0/threaded"
            },
            {
              "name": "ADV-2006-2388",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/2388"
            },
            {
              "name": "20726",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20726"
            },
            {
              "name": "oval:org.mitre.oval:def:11253",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11253"
            },
            {
              "name": "ADV-2006-2351",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/2351"
            },
            {
              "name": "21327",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/21327"
            },
            {
              "name": "RHSA-2006:0515",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2006-0515.html"
            },
            {
              "name": "ADV-2006-2389",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/2389"
            },
            {
              "name": "21647",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/21647"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-18.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://issues.rpath.com/browse/RPL-526"
            },
            {
              "name": "20651",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20651"
            },
            {
              "name": "20683",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20683"
            },
            {
              "name": "20650",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20650"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://support.avaya.com/elmodocs2/security/ASA-2006-148.htm"
            },
            {
              "name": "20782",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20782"
            },
            {
              "name": "ADV-2006-3135",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/3135"
            },
            {
              "name": "1016295",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://securitytracker.com/id?1016295"
            },
            {
              "name": "20694",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20694"
            },
            {
              "name": "20473",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20473"
            },
            {
              "name": "ADV-2006-2189",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/2189"
            },
            {
              "name": "20060721 rPSA-2006-0134-1 sendmail sendmail-cf",
              "tags": [
                "mailing-list",
                "x_refsource_BUGTRAQ"
              ],
              "url": "http://www.securityfocus.com/archive/1/440744/100/0/threaded"
            },
            {
              "name": "20060601-01-P",
              "tags": [
                "vendor-advisory",
                "x_refsource_SGI"
              ],
              "url": "ftp://patches.sgi.com/support/free/security/advisories/20060601-01-P"
            },
            {
              "name": "ADV-2006-2798",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/2798"
            },
            {
              "name": "102460",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102460-1"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.sendmail.com/security/advisories/SA-200605-01.txt.asc"
            },
            {
              "name": "20060602-01-U",
              "tags": [
                "vendor-advisory",
                "x_refsource_SGI"
              ],
              "url": "ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc"
            },
            {
              "name": "MDKSA-2006:104",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:104"
            },
            {
              "name": "sendmail-multipart-mime-dos(27128)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27128"
            },
            {
              "name": "20673",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20673"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.f-secure.com/security/fsc-2006-5.shtml"
            },
            {
              "name": "20060621 Re: Sendmail MIME DoS vulnerability",
              "tags": [
                "mailing-list",
                "x_refsource_BUGTRAQ"
              ],
              "url": "http://www.securityfocus.com/archive/1/438241/100/0/threaded"
            },
            {
              "name": "21612",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/21612"
            },
            {
              "name": "20654",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20654"
            },
            {
              "name": "ADV-2006-2390",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/2390"
            },
            {
              "name": "SSA:2006-166-01",
              "tags": [
                "vendor-advisory",
                "x_refsource_SLACKWARE"
              ],
              "url": "http://slackware.com/security/viewer.php?l=slackware-security\u0026y=2006\u0026m=slackware-security.631382"
            },
            {
              "name": "GLSA-200606-19",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://www.gentoo.org/security/en/glsa/glsa-200606-19.xml"
            },
            {
              "name": "18433",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/18433"
            },
            {
              "name": "20675",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20675"
            },
            {
              "name": "SUSE-SA:2006:032",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.suse.com/archive/suse-security-announce/2006-Jun/0006.html"
            },
            {
              "name": "FreeBSD-SA-06:17.sendmail",
              "tags": [
                "vendor-advisory",
                "x_refsource_FREEBSD"
              ],
              "url": "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:17.sendmail.asc"
            },
            {
              "name": "20060620 Sendmail MIME DoS vulnerability",
              "tags": [
                "mailing-list",
                "x_refsource_BUGTRAQ"
              ],
              "url": "http://www.securityfocus.com/archive/1/437928/100/0/threaded"
            },
            {
              "name": "SSRT061159",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://www.securityfocus.com/archive/1/442939/100/0/threaded"
            },
            {
              "name": "VU#146718",
              "tags": [
                "third-party-advisory",
                "x_refsource_CERT-VN"
              ],
              "url": "http://www.kb.cert.org/vuls/id/146718"
            },
            {
              "name": "SSRT061135",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
            },
            {
              "name": "15779",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/15779"
            },
            {
              "name": "20641",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20641"
            },
            {
              "name": "20679",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20679"
            },
            {
              "name": "26197",
              "tags": [
                "vdb-entry",
                "x_refsource_OSVDB"
              ],
              "url": "http://www.osvdb.org/26197"
            },
            {
              "name": "21042",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/21042"
            },
            {
              "name": "21160",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/21160"
            },
            {
              "name": "IY85930",
              "tags": [
                "vendor-advisory",
                "x_refsource_AIXAPAR"
              ],
              "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY85930\u0026apar=only"
            },
            {
              "name": "20060624 Re: Sendmail MIME DoS vulnerability",
              "tags": [
                "mailing-list",
                "x_refsource_BUGTRAQ"
              ],
              "url": "http://www.securityfocus.com/archive/1/438330/100/0/threaded"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cert@cert.org",
              "ID": "CVE-2006-1173",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "IY85415",
                  "refsource": "AIXAPAR",
                  "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY85415\u0026apar=only"
                },
                {
                  "name": "HPSBTU02116",
                  "refsource": "HP",
                  "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
                },
                {
                  "name": "DSA-1155",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2006/dsa-1155"
                },
                {
                  "name": "[3.8] 008: SECURITY FIX: June 15, 2006",
                  "refsource": "OPENBSD",
                  "url": "http://www.openbsd.org/errata38.html#sendmail2"
                },
                {
                  "name": "20684",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20684"
                },
                {
                  "name": "HPSBUX02124",
                  "refsource": "HP",
                  "url": "http://www.securityfocus.com/archive/1/442939/100/0/threaded"
                },
                {
                  "name": "ADV-2006-2388",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/2388"
                },
                {
                  "name": "20726",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20726"
                },
                {
                  "name": "oval:org.mitre.oval:def:11253",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11253"
                },
                {
                  "name": "ADV-2006-2351",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/2351"
                },
                {
                  "name": "21327",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/21327"
                },
                {
                  "name": "RHSA-2006:0515",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2006-0515.html"
                },
                {
                  "name": "ADV-2006-2389",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/2389"
                },
                {
                  "name": "21647",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/21647"
                },
                {
                  "name": "http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-18.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-18.html"
                },
                {
                  "name": "https://issues.rpath.com/browse/RPL-526",
                  "refsource": "CONFIRM",
                  "url": "https://issues.rpath.com/browse/RPL-526"
                },
                {
                  "name": "20651",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20651"
                },
                {
                  "name": "20683",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20683"
                },
                {
                  "name": "20650",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20650"
                },
                {
                  "name": "http://support.avaya.com/elmodocs2/security/ASA-2006-148.htm",
                  "refsource": "CONFIRM",
                  "url": "http://support.avaya.com/elmodocs2/security/ASA-2006-148.htm"
                },
                {
                  "name": "20782",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20782"
                },
                {
                  "name": "ADV-2006-3135",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/3135"
                },
                {
                  "name": "1016295",
                  "refsource": "SECTRACK",
                  "url": "http://securitytracker.com/id?1016295"
                },
                {
                  "name": "20694",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20694"
                },
                {
                  "name": "20473",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20473"
                },
                {
                  "name": "ADV-2006-2189",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/2189"
                },
                {
                  "name": "20060721 rPSA-2006-0134-1 sendmail sendmail-cf",
                  "refsource": "BUGTRAQ",
                  "url": "http://www.securityfocus.com/archive/1/440744/100/0/threaded"
                },
                {
                  "name": "20060601-01-P",
                  "refsource": "SGI",
                  "url": "ftp://patches.sgi.com/support/free/security/advisories/20060601-01-P"
                },
                {
                  "name": "ADV-2006-2798",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/2798"
                },
                {
                  "name": "102460",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102460-1"
                },
                {
                  "name": "http://www.sendmail.com/security/advisories/SA-200605-01.txt.asc",
                  "refsource": "CONFIRM",
                  "url": "http://www.sendmail.com/security/advisories/SA-200605-01.txt.asc"
                },
                {
                  "name": "20060602-01-U",
                  "refsource": "SGI",
                  "url": "ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc"
                },
                {
                  "name": "MDKSA-2006:104",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:104"
                },
                {
                  "name": "sendmail-multipart-mime-dos(27128)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27128"
                },
                {
                  "name": "20673",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20673"
                },
                {
                  "name": "http://www.f-secure.com/security/fsc-2006-5.shtml",
                  "refsource": "CONFIRM",
                  "url": "http://www.f-secure.com/security/fsc-2006-5.shtml"
                },
                {
                  "name": "20060621 Re: Sendmail MIME DoS vulnerability",
                  "refsource": "BUGTRAQ",
                  "url": "http://www.securityfocus.com/archive/1/438241/100/0/threaded"
                },
                {
                  "name": "21612",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/21612"
                },
                {
                  "name": "20654",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20654"
                },
                {
                  "name": "ADV-2006-2390",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/2390"
                },
                {
                  "name": "SSA:2006-166-01",
                  "refsource": "SLACKWARE",
                  "url": "http://slackware.com/security/viewer.php?l=slackware-security\u0026y=2006\u0026m=slackware-security.631382"
                },
                {
                  "name": "GLSA-200606-19",
                  "refsource": "GENTOO",
                  "url": "http://www.gentoo.org/security/en/glsa/glsa-200606-19.xml"
                },
                {
                  "name": "18433",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/18433"
                },
                {
                  "name": "20675",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20675"
                },
                {
                  "name": "SUSE-SA:2006:032",
                  "refsource": "SUSE",
                  "url": "http://lists.suse.com/archive/suse-security-announce/2006-Jun/0006.html"
                },
                {
                  "name": "FreeBSD-SA-06:17.sendmail",
                  "refsource": "FREEBSD",
                  "url": "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:17.sendmail.asc"
                },
                {
                  "name": "20060620 Sendmail MIME DoS vulnerability",
                  "refsource": "BUGTRAQ",
                  "url": "http://www.securityfocus.com/archive/1/437928/100/0/threaded"
                },
                {
                  "name": "SSRT061159",
                  "refsource": "HP",
                  "url": "http://www.securityfocus.com/archive/1/442939/100/0/threaded"
                },
                {
                  "name": "VU#146718",
                  "refsource": "CERT-VN",
                  "url": "http://www.kb.cert.org/vuls/id/146718"
                },
                {
                  "name": "SSRT061135",
                  "refsource": "HP",
                  "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
                },
                {
                  "name": "15779",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/15779"
                },
                {
                  "name": "20641",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20641"
                },
                {
                  "name": "20679",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20679"
                },
                {
                  "name": "26197",
                  "refsource": "OSVDB",
                  "url": "http://www.osvdb.org/26197"
                },
                {
                  "name": "21042",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/21042"
                },
                {
                  "name": "21160",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/21160"
                },
                {
                  "name": "IY85930",
                  "refsource": "AIXAPAR",
                  "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY85930\u0026apar=only"
                },
                {
                  "name": "20060624 Re: Sendmail MIME DoS vulnerability",
                  "refsource": "BUGTRAQ",
                  "url": "http://www.securityfocus.com/archive/1/438330/100/0/threaded"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "37e5125f-f79b-445b-8fad-9564f167944b",
        "assignerShortName": "certcc",
        "cveId": "CVE-2006-1173",
        "datePublished": "2006-06-07T23:00:00.000Z",
        "dateReserved": "2006-03-12T00:00:00.000Z",
        "dateUpdated": "2024-08-07T17:03:28.441Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2006-0058 (GCVE-0-2006-0058)

    Vulnerability from cvelistv5 – Published: 2006-03-22 20:00 – Updated: 2024-08-07 16:18
    VLAI
    Summary
    Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.vupen.com/english/advisories/2006/1529 vdb-entryx_refsource_VUPEN
    http://itrc.hp.com/service/cki/docDisplay.do?docI… vendor-advisoryx_refsource_HP
    http://secunia.com/advisories/19450 third-party-advisoryx_refsource_SECUNIA
    http://www.debian.org/security/2006/dsa-1015 vendor-advisoryx_refsource_DEBIAN
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://www14.software.ibm.com/webapp/set2/sas/f/h… x_refsource_CONFIRM
    http://www.openbsd.org/errata38.html#sendmail vendor-advisoryx_refsource_OPENBSD
    http://www.kb.cert.org/vuls/id/834865 third-party-advisoryx_refsource_CERT-VN
    ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006… vendor-advisoryx_refsource_SCO
    http://secunia.com/advisories/19342 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2006/1049 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/19774 third-party-advisoryx_refsource_SECUNIA
    ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories… vendor-advisoryx_refsource_FREEBSD
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    ftp://patches.sgi.com/support/free/security/advis… vendor-advisoryx_refsource_SGI
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://secunia.com/advisories/19404 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/19367 third-party-advisoryx_refsource_SECUNIA
    http://www.openpkg.org/security/advisories/OpenPK… vendor-advisoryx_refsource_OPENPKG
    http://www.vupen.com/english/advisories/2006/1051 vdb-entryx_refsource_VUPEN
    http://www.securityfocus.com/archive/1/428536/100… mailing-listx_refsource_BUGTRAQ
    http://www.f-secure.com/security/fsc-2006-2.shtml x_refsource_CONFIRM
    http://securityreason.com/securityalert/743 third-party-advisoryx_refsource_SREASON
    http://securitytracker.com/id?1015801 vdb-entryx_refsource_SECTRACK
    http://h20000.www2.hp.com/bizsupport/TechSupport/… vendor-advisoryx_refsource_HP
    http://secunia.com/advisories/19363 third-party-advisoryx_refsource_SECUNIA
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    http://www.us-cert.gov/cas/techalerts/TA06-081A.html third-party-advisoryx_refsource_CERT
    http://secunia.com/advisories/20723 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/20243 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/19407 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2006/2189 vdb-entryx_refsource_VUPEN
    http://www.redhat.com/archives/fedora-announce-li… vendor-advisoryx_refsource_FEDORA
    ftp://patches.sgi.com/support/free/security/advis… vendor-advisoryx_refsource_SGI
    http://www.iss.net/threats/216.html third-party-advisoryx_refsource_ISS
    http://secunia.com/advisories/19466 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/19368 third-party-advisoryx_refsource_SECUNIA
    http://support.avaya.com/elmodocs2/security/ASA-2… x_refsource_CONFIRM
    http://www.ciac.org/ciac/bulletins/q-151.shtml third-party-advisorygovernment-resourcex_refsource_CIAC
    http://support.avaya.com/elmodocs2/security/ASA-2… x_refsource_CONFIRM
    http://secunia.com/advisories/19345 third-party-advisoryx_refsource_SECUNIA
    http://securityreason.com/securityalert/612 third-party-advisoryx_refsource_SREASON
    http://www.redhat.com/archives/fedora-announce-li… vendor-advisoryx_refsource_FEDORA
    http://secunia.com/advisories/19346 third-party-advisoryx_refsource_SECUNIA
    http://slackware.com/security/viewer.php?l=slackw… vendor-advisoryx_refsource_SLACKWARE
    http://www-1.ibm.com/support/search.wss?rs=0&q=IY… vendor-advisoryx_refsource_AIXAPAR
    http://www14.software.ibm.com/webapp/set2/subscri… x_refsource_CONFIRM
    http://www.gentoo.org/security/en/glsa/glsa-20060… vendor-advisoryx_refsource_GENTOO
    http://www-1.ibm.com/support/search.wss?rs=0&q=IY… vendor-advisoryx_refsource_AIXAPAR
    http://www-1.ibm.com/support/search.wss?rs=0&q=IY… vendor-advisoryx_refsource_AIXAPAR
    http://www.vupen.com/english/advisories/2006/1068 vdb-entryx_refsource_VUPEN
    http://www.redhat.com/support/errata/RHSA-2006-02… vendor-advisoryx_refsource_REDHAT
    http://www.vupen.com/english/advisories/2006/2490 vdb-entryx_refsource_VUPEN
    http://www.vupen.com/english/advisories/2006/1072 vdb-entryx_refsource_VUPEN
    http://www.securityfocus.com/archive/1/428656/100… vendor-advisoryx_refsource_FEDORA
    http://secunia.com/advisories/19360 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/19532 third-party-advisoryx_refsource_SECUNIA
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://secunia.com/advisories/19361 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/19676 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/19356 third-party-advisoryx_refsource_SECUNIA
    http://www.novell.com/linux/security/advisories/2… vendor-advisoryx_refsource_SUSE
    http://www.osvdb.org/24037 vdb-entryx_refsource_OSVDB
    http://secunia.com/advisories/19349 third-party-advisoryx_refsource_SECUNIA
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://secunia.com/advisories/19394 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2006/1139 vdb-entryx_refsource_VUPEN
    http://www.vupen.com/english/advisories/2006/1157 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/19533 third-party-advisoryx_refsource_SECUNIA
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    ftp://ftp.netbsd.org/pub/NetBSD/security/advisori… vendor-advisoryx_refsource_NETBSD
    http://www.securityfocus.com/bid/17192 vdb-entryx_refsource_BID
    http://www.redhat.com/support/errata/RHSA-2006-02… vendor-advisoryx_refsource_REDHAT
    http://www.sendmail.com/company/advisory/index.shtml x_refsource_CONFIRM
    Date Public
    2006-03-22 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T16:18:20.809Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "ADV-2006-1529",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/1529"
              },
              {
                "name": "HPSBTU02116",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
              },
              {
                "name": "19450",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19450"
              },
              {
                "name": "DSA-1015",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2006/dsa-1015"
              },
              {
                "name": "MDKSA-2006:058",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:058"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688"
              },
              {
                "name": "[3.8] 006: SECURITY FIX: March 25, 2006",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_OPENBSD",
                  "x_transferred"
                ],
                "url": "http://www.openbsd.org/errata38.html#sendmail"
              },
              {
                "name": "VU#834865",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_CERT-VN",
                  "x_transferred"
                ],
                "url": "http://www.kb.cert.org/vuls/id/834865"
              },
              {
                "name": "SCOSA-2006.24",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SCO",
                  "x_transferred"
                ],
                "url": "ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.24/SCOSA-2006.24.txt"
              },
              {
                "name": "19342",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19342"
              },
              {
                "name": "ADV-2006-1049",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/1049"
              },
              {
                "name": "19774",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19774"
              },
              {
                "name": "FreeBSD-SA-06:13",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FREEBSD",
                  "x_transferred"
                ],
                "url": "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:13.sendmail.asc"
              },
              {
                "name": "oval:org.mitre.oval:def:11074",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11074"
              },
              {
                "name": "20060401-01-U",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SGI",
                  "x_transferred"
                ],
                "url": "ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U"
              },
              {
                "name": "200494",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-66-200494-1"
              },
              {
                "name": "19404",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19404"
              },
              {
                "name": "19367",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19367"
              },
              {
                "name": "OpenPKG-SA-2006.007",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_OPENPKG",
                  "x_transferred"
                ],
                "url": "http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.007-sendmail.html"
              },
              {
                "name": "ADV-2006-1051",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/1051"
              },
              {
                "name": "20060322 sendmail vuln advisories (CVE-2006-0058)",
                "tags": [
                  "mailing-list",
                  "x_refsource_BUGTRAQ",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/428536/100/0/threaded"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.f-secure.com/security/fsc-2006-2.shtml"
              },
              {
                "name": "743",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SREASON",
                  "x_transferred"
                ],
                "url": "http://securityreason.com/securityalert/743"
              },
              {
                "name": "1015801",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://securitytracker.com/id?1015801"
              },
              {
                "name": "HPSBUX02108",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00629555"
              },
              {
                "name": "19363",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19363"
              },
              {
                "name": "smtp-timeout-bo(24584)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/24584"
              },
              {
                "name": "TA06-081A",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_CERT",
                  "x_transferred"
                ],
                "url": "http://www.us-cert.gov/cas/techalerts/TA06-081A.html"
              },
              {
                "name": "20723",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20723"
              },
              {
                "name": "20243",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/20243"
              },
              {
                "name": "19407",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19407"
              },
              {
                "name": "ADV-2006-2189",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/2189"
              },
              {
                "name": "FEDORA-2006-194",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00017.html"
              },
              {
                "name": "20060302-01-P",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SGI",
                  "x_transferred"
                ],
                "url": "ftp://patches.sgi.com/support/free/security/advisories/20060302-01-P"
              },
              {
                "name": "20060322 Sendmail Remote Signal Handling Vulnerability",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_ISS",
                  "x_transferred"
                ],
                "url": "http://www.iss.net/threats/216.html"
              },
              {
                "name": "19466",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19466"
              },
              {
                "name": "19368",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19368"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm"
              },
              {
                "name": "Q-151",
                "tags": [
                  "third-party-advisory",
                  "government-resource",
                  "x_refsource_CIAC",
                  "x_transferred"
                ],
                "url": "http://www.ciac.org/ciac/bulletins/q-151.shtml"
              },
              {
                "name": "SSRT061133",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00629555"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://support.avaya.com/elmodocs2/security/ASA-2006-074.htm"
              },
              {
                "name": "19345",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19345"
              },
              {
                "name": "612",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SREASON",
                  "x_transferred"
                ],
                "url": "http://securityreason.com/securityalert/612"
              },
              {
                "name": "FEDORA-2006-193",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00018.html"
              },
              {
                "name": "19346",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19346"
              },
              {
                "name": "SSA:2006-081-01",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SLACKWARE",
                  "x_transferred"
                ],
                "url": "http://slackware.com/security/viewer.php?l=slackware-security\u0026y=2006\u0026m=slackware-security.619600"
              },
              {
                "name": "IY82992",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_AIXAPAR",
                  "x_transferred"
                ],
                "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY82992\u0026apar=only"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18\u0026ID=2751"
              },
              {
                "name": "GLSA-200603-21",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://www.gentoo.org/security/en/glsa/glsa-200603-21.xml"
              },
              {
                "name": "IY82994",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_AIXAPAR",
                  "x_transferred"
                ],
                "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY82994\u0026apar=only"
              },
              {
                "name": "IY82993",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_AIXAPAR",
                  "x_transferred"
                ],
                "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY82993\u0026apar=only"
              },
              {
                "name": "ADV-2006-1068",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/1068"
              },
              {
                "name": "RHSA-2006:0265",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2006-0265.html"
              },
              {
                "name": "ADV-2006-2490",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/2490"
              },
              {
                "name": "ADV-2006-1072",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/1072"
              },
              {
                "name": "FLSA:186277",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/428656/100/0/threaded"
              },
              {
                "name": "19360",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19360"
              },
              {
                "name": "19532",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19532"
              },
              {
                "name": "102324",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102324-1"
              },
              {
                "name": "19361",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19361"
              },
              {
                "name": "19676",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19676"
              },
              {
                "name": "19356",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19356"
              },
              {
                "name": "SUSE-SA:2006:017",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://www.novell.com/linux/security/advisories/2006_17_sendmail.html"
              },
              {
                "name": "24037",
                "tags": [
                  "vdb-entry",
                  "x_refsource_OSVDB",
                  "x_transferred"
                ],
                "url": "http://www.osvdb.org/24037"
              },
              {
                "name": "19349",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19349"
              },
              {
                "name": "102262",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102262-1"
              },
              {
                "name": "19394",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19394"
              },
              {
                "name": "SSRT061135",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_HP",
                  "x_transferred"
                ],
                "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
              },
              {
                "name": "ADV-2006-1139",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/1139"
              },
              {
                "name": "ADV-2006-1157",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2006/1157"
              },
              {
                "name": "19533",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/19533"
              },
              {
                "name": "oval:org.mitre.oval:def:1689",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1689"
              },
              {
                "name": "NetBSD-SA2006-010",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_NETBSD",
                  "x_transferred"
                ],
                "url": "ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-010.txt.asc"
              },
              {
                "name": "17192",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/17192"
              },
              {
                "name": "RHSA-2006:0264",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2006-0264.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.sendmail.com/company/advisory/index.shtml"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2006-03-22T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-10-19T14:57:01.000Z",
            "orgId": "37e5125f-f79b-445b-8fad-9564f167944b",
            "shortName": "certcc"
          },
          "references": [
            {
              "name": "ADV-2006-1529",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/1529"
            },
            {
              "name": "HPSBTU02116",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
            },
            {
              "name": "19450",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19450"
            },
            {
              "name": "DSA-1015",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2006/dsa-1015"
            },
            {
              "name": "MDKSA-2006:058",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:058"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688"
            },
            {
              "name": "[3.8] 006: SECURITY FIX: March 25, 2006",
              "tags": [
                "vendor-advisory",
                "x_refsource_OPENBSD"
              ],
              "url": "http://www.openbsd.org/errata38.html#sendmail"
            },
            {
              "name": "VU#834865",
              "tags": [
                "third-party-advisory",
                "x_refsource_CERT-VN"
              ],
              "url": "http://www.kb.cert.org/vuls/id/834865"
            },
            {
              "name": "SCOSA-2006.24",
              "tags": [
                "vendor-advisory",
                "x_refsource_SCO"
              ],
              "url": "ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.24/SCOSA-2006.24.txt"
            },
            {
              "name": "19342",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19342"
            },
            {
              "name": "ADV-2006-1049",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/1049"
            },
            {
              "name": "19774",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19774"
            },
            {
              "name": "FreeBSD-SA-06:13",
              "tags": [
                "vendor-advisory",
                "x_refsource_FREEBSD"
              ],
              "url": "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:13.sendmail.asc"
            },
            {
              "name": "oval:org.mitre.oval:def:11074",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11074"
            },
            {
              "name": "20060401-01-U",
              "tags": [
                "vendor-advisory",
                "x_refsource_SGI"
              ],
              "url": "ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U"
            },
            {
              "name": "200494",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-66-200494-1"
            },
            {
              "name": "19404",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19404"
            },
            {
              "name": "19367",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19367"
            },
            {
              "name": "OpenPKG-SA-2006.007",
              "tags": [
                "vendor-advisory",
                "x_refsource_OPENPKG"
              ],
              "url": "http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.007-sendmail.html"
            },
            {
              "name": "ADV-2006-1051",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/1051"
            },
            {
              "name": "20060322 sendmail vuln advisories (CVE-2006-0058)",
              "tags": [
                "mailing-list",
                "x_refsource_BUGTRAQ"
              ],
              "url": "http://www.securityfocus.com/archive/1/428536/100/0/threaded"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.f-secure.com/security/fsc-2006-2.shtml"
            },
            {
              "name": "743",
              "tags": [
                "third-party-advisory",
                "x_refsource_SREASON"
              ],
              "url": "http://securityreason.com/securityalert/743"
            },
            {
              "name": "1015801",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://securitytracker.com/id?1015801"
            },
            {
              "name": "HPSBUX02108",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00629555"
            },
            {
              "name": "19363",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19363"
            },
            {
              "name": "smtp-timeout-bo(24584)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/24584"
            },
            {
              "name": "TA06-081A",
              "tags": [
                "third-party-advisory",
                "x_refsource_CERT"
              ],
              "url": "http://www.us-cert.gov/cas/techalerts/TA06-081A.html"
            },
            {
              "name": "20723",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20723"
            },
            {
              "name": "20243",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/20243"
            },
            {
              "name": "19407",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19407"
            },
            {
              "name": "ADV-2006-2189",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/2189"
            },
            {
              "name": "FEDORA-2006-194",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00017.html"
            },
            {
              "name": "20060302-01-P",
              "tags": [
                "vendor-advisory",
                "x_refsource_SGI"
              ],
              "url": "ftp://patches.sgi.com/support/free/security/advisories/20060302-01-P"
            },
            {
              "name": "20060322 Sendmail Remote Signal Handling Vulnerability",
              "tags": [
                "third-party-advisory",
                "x_refsource_ISS"
              ],
              "url": "http://www.iss.net/threats/216.html"
            },
            {
              "name": "19466",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19466"
            },
            {
              "name": "19368",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19368"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm"
            },
            {
              "name": "Q-151",
              "tags": [
                "third-party-advisory",
                "government-resource",
                "x_refsource_CIAC"
              ],
              "url": "http://www.ciac.org/ciac/bulletins/q-151.shtml"
            },
            {
              "name": "SSRT061133",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00629555"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://support.avaya.com/elmodocs2/security/ASA-2006-074.htm"
            },
            {
              "name": "19345",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19345"
            },
            {
              "name": "612",
              "tags": [
                "third-party-advisory",
                "x_refsource_SREASON"
              ],
              "url": "http://securityreason.com/securityalert/612"
            },
            {
              "name": "FEDORA-2006-193",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00018.html"
            },
            {
              "name": "19346",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19346"
            },
            {
              "name": "SSA:2006-081-01",
              "tags": [
                "vendor-advisory",
                "x_refsource_SLACKWARE"
              ],
              "url": "http://slackware.com/security/viewer.php?l=slackware-security\u0026y=2006\u0026m=slackware-security.619600"
            },
            {
              "name": "IY82992",
              "tags": [
                "vendor-advisory",
                "x_refsource_AIXAPAR"
              ],
              "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY82992\u0026apar=only"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18\u0026ID=2751"
            },
            {
              "name": "GLSA-200603-21",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://www.gentoo.org/security/en/glsa/glsa-200603-21.xml"
            },
            {
              "name": "IY82994",
              "tags": [
                "vendor-advisory",
                "x_refsource_AIXAPAR"
              ],
              "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY82994\u0026apar=only"
            },
            {
              "name": "IY82993",
              "tags": [
                "vendor-advisory",
                "x_refsource_AIXAPAR"
              ],
              "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY82993\u0026apar=only"
            },
            {
              "name": "ADV-2006-1068",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/1068"
            },
            {
              "name": "RHSA-2006:0265",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2006-0265.html"
            },
            {
              "name": "ADV-2006-2490",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/2490"
            },
            {
              "name": "ADV-2006-1072",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/1072"
            },
            {
              "name": "FLSA:186277",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "http://www.securityfocus.com/archive/1/428656/100/0/threaded"
            },
            {
              "name": "19360",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19360"
            },
            {
              "name": "19532",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19532"
            },
            {
              "name": "102324",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102324-1"
            },
            {
              "name": "19361",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19361"
            },
            {
              "name": "19676",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19676"
            },
            {
              "name": "19356",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19356"
            },
            {
              "name": "SUSE-SA:2006:017",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://www.novell.com/linux/security/advisories/2006_17_sendmail.html"
            },
            {
              "name": "24037",
              "tags": [
                "vdb-entry",
                "x_refsource_OSVDB"
              ],
              "url": "http://www.osvdb.org/24037"
            },
            {
              "name": "19349",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19349"
            },
            {
              "name": "102262",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102262-1"
            },
            {
              "name": "19394",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19394"
            },
            {
              "name": "SSRT061135",
              "tags": [
                "vendor-advisory",
                "x_refsource_HP"
              ],
              "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
            },
            {
              "name": "ADV-2006-1139",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/1139"
            },
            {
              "name": "ADV-2006-1157",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2006/1157"
            },
            {
              "name": "19533",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/19533"
            },
            {
              "name": "oval:org.mitre.oval:def:1689",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1689"
            },
            {
              "name": "NetBSD-SA2006-010",
              "tags": [
                "vendor-advisory",
                "x_refsource_NETBSD"
              ],
              "url": "ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-010.txt.asc"
            },
            {
              "name": "17192",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/17192"
            },
            {
              "name": "RHSA-2006:0264",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2006-0264.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.sendmail.com/company/advisory/index.shtml"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cert@cert.org",
              "ID": "CVE-2006-0058",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "ADV-2006-1529",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/1529"
                },
                {
                  "name": "HPSBTU02116",
                  "refsource": "HP",
                  "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
                },
                {
                  "name": "19450",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19450"
                },
                {
                  "name": "DSA-1015",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2006/dsa-1015"
                },
                {
                  "name": "MDKSA-2006:058",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2006:058"
                },
                {
                  "name": "http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688",
                  "refsource": "CONFIRM",
                  "url": "http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688"
                },
                {
                  "name": "[3.8] 006: SECURITY FIX: March 25, 2006",
                  "refsource": "OPENBSD",
                  "url": "http://www.openbsd.org/errata38.html#sendmail"
                },
                {
                  "name": "VU#834865",
                  "refsource": "CERT-VN",
                  "url": "http://www.kb.cert.org/vuls/id/834865"
                },
                {
                  "name": "SCOSA-2006.24",
                  "refsource": "SCO",
                  "url": "ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.24/SCOSA-2006.24.txt"
                },
                {
                  "name": "19342",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19342"
                },
                {
                  "name": "ADV-2006-1049",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/1049"
                },
                {
                  "name": "19774",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19774"
                },
                {
                  "name": "FreeBSD-SA-06:13",
                  "refsource": "FREEBSD",
                  "url": "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:13.sendmail.asc"
                },
                {
                  "name": "oval:org.mitre.oval:def:11074",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11074"
                },
                {
                  "name": "20060401-01-U",
                  "refsource": "SGI",
                  "url": "ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U"
                },
                {
                  "name": "200494",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-66-200494-1"
                },
                {
                  "name": "19404",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19404"
                },
                {
                  "name": "19367",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19367"
                },
                {
                  "name": "OpenPKG-SA-2006.007",
                  "refsource": "OPENPKG",
                  "url": "http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.007-sendmail.html"
                },
                {
                  "name": "ADV-2006-1051",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/1051"
                },
                {
                  "name": "20060322 sendmail vuln advisories (CVE-2006-0058)",
                  "refsource": "BUGTRAQ",
                  "url": "http://www.securityfocus.com/archive/1/428536/100/0/threaded"
                },
                {
                  "name": "http://www.f-secure.com/security/fsc-2006-2.shtml",
                  "refsource": "CONFIRM",
                  "url": "http://www.f-secure.com/security/fsc-2006-2.shtml"
                },
                {
                  "name": "743",
                  "refsource": "SREASON",
                  "url": "http://securityreason.com/securityalert/743"
                },
                {
                  "name": "1015801",
                  "refsource": "SECTRACK",
                  "url": "http://securitytracker.com/id?1015801"
                },
                {
                  "name": "HPSBUX02108",
                  "refsource": "HP",
                  "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00629555"
                },
                {
                  "name": "19363",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19363"
                },
                {
                  "name": "smtp-timeout-bo(24584)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/24584"
                },
                {
                  "name": "TA06-081A",
                  "refsource": "CERT",
                  "url": "http://www.us-cert.gov/cas/techalerts/TA06-081A.html"
                },
                {
                  "name": "20723",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20723"
                },
                {
                  "name": "20243",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/20243"
                },
                {
                  "name": "19407",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19407"
                },
                {
                  "name": "ADV-2006-2189",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/2189"
                },
                {
                  "name": "FEDORA-2006-194",
                  "refsource": "FEDORA",
                  "url": "http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00017.html"
                },
                {
                  "name": "20060302-01-P",
                  "refsource": "SGI",
                  "url": "ftp://patches.sgi.com/support/free/security/advisories/20060302-01-P"
                },
                {
                  "name": "20060322 Sendmail Remote Signal Handling Vulnerability",
                  "refsource": "ISS",
                  "url": "http://www.iss.net/threats/216.html"
                },
                {
                  "name": "19466",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19466"
                },
                {
                  "name": "19368",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19368"
                },
                {
                  "name": "http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm",
                  "refsource": "CONFIRM",
                  "url": "http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm"
                },
                {
                  "name": "Q-151",
                  "refsource": "CIAC",
                  "url": "http://www.ciac.org/ciac/bulletins/q-151.shtml"
                },
                {
                  "name": "SSRT061133",
                  "refsource": "HP",
                  "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en\u0026cc=us\u0026objectID=c00629555"
                },
                {
                  "name": "http://support.avaya.com/elmodocs2/security/ASA-2006-074.htm",
                  "refsource": "CONFIRM",
                  "url": "http://support.avaya.com/elmodocs2/security/ASA-2006-074.htm"
                },
                {
                  "name": "19345",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19345"
                },
                {
                  "name": "612",
                  "refsource": "SREASON",
                  "url": "http://securityreason.com/securityalert/612"
                },
                {
                  "name": "FEDORA-2006-193",
                  "refsource": "FEDORA",
                  "url": "http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00018.html"
                },
                {
                  "name": "19346",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19346"
                },
                {
                  "name": "SSA:2006-081-01",
                  "refsource": "SLACKWARE",
                  "url": "http://slackware.com/security/viewer.php?l=slackware-security\u0026y=2006\u0026m=slackware-security.619600"
                },
                {
                  "name": "IY82992",
                  "refsource": "AIXAPAR",
                  "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY82992\u0026apar=only"
                },
                {
                  "name": "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18\u0026ID=2751",
                  "refsource": "CONFIRM",
                  "url": "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18\u0026ID=2751"
                },
                {
                  "name": "GLSA-200603-21",
                  "refsource": "GENTOO",
                  "url": "http://www.gentoo.org/security/en/glsa/glsa-200603-21.xml"
                },
                {
                  "name": "IY82994",
                  "refsource": "AIXAPAR",
                  "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY82994\u0026apar=only"
                },
                {
                  "name": "IY82993",
                  "refsource": "AIXAPAR",
                  "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=IY82993\u0026apar=only"
                },
                {
                  "name": "ADV-2006-1068",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/1068"
                },
                {
                  "name": "RHSA-2006:0265",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2006-0265.html"
                },
                {
                  "name": "ADV-2006-2490",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/2490"
                },
                {
                  "name": "ADV-2006-1072",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/1072"
                },
                {
                  "name": "FLSA:186277",
                  "refsource": "FEDORA",
                  "url": "http://www.securityfocus.com/archive/1/428656/100/0/threaded"
                },
                {
                  "name": "19360",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19360"
                },
                {
                  "name": "19532",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19532"
                },
                {
                  "name": "102324",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102324-1"
                },
                {
                  "name": "19361",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19361"
                },
                {
                  "name": "19676",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19676"
                },
                {
                  "name": "19356",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19356"
                },
                {
                  "name": "SUSE-SA:2006:017",
                  "refsource": "SUSE",
                  "url": "http://www.novell.com/linux/security/advisories/2006_17_sendmail.html"
                },
                {
                  "name": "24037",
                  "refsource": "OSVDB",
                  "url": "http://www.osvdb.org/24037"
                },
                {
                  "name": "19349",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19349"
                },
                {
                  "name": "102262",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102262-1"
                },
                {
                  "name": "19394",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19394"
                },
                {
                  "name": "SSRT061135",
                  "refsource": "HP",
                  "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635"
                },
                {
                  "name": "ADV-2006-1139",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/1139"
                },
                {
                  "name": "ADV-2006-1157",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2006/1157"
                },
                {
                  "name": "19533",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/19533"
                },
                {
                  "name": "oval:org.mitre.oval:def:1689",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1689"
                },
                {
                  "name": "NetBSD-SA2006-010",
                  "refsource": "NETBSD",
                  "url": "ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-010.txt.asc"
                },
                {
                  "name": "17192",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/17192"
                },
                {
                  "name": "RHSA-2006:0264",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2006-0264.html"
                },
                {
                  "name": "http://www.sendmail.com/company/advisory/index.shtml",
                  "refsource": "CONFIRM",
                  "url": "http://www.sendmail.com/company/advisory/index.shtml"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "37e5125f-f79b-445b-8fad-9564f167944b",
        "assignerShortName": "certcc",
        "cveId": "CVE-2006-0058",
        "datePublished": "2006-03-22T20:00:00.000Z",
        "dateReserved": "2006-01-01T00:00:00.000Z",
        "dateUpdated": "2024-08-07T16:18:20.809Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2005-2070 (GCVE-0-2005-2070)

    Vulnerability from cvelistv5 – Published: 2005-06-29 04:00 – Updated: 2024-08-07 22:15
    VLAI
    Summary
    The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a denial of service by keeping an open connection, which prevents ClamAV from reloading.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.novell.com/linux/security/advisories/2… vendor-advisoryx_refsource_SUSE
    http://seclists.org/lists/bugtraq/2005/Jun/0197.html mailing-listx_refsource_BUGTRAQ
    http://www.debian.org/security/2005/dsa-737 vendor-advisoryx_refsource_DEBIAN
    http://www.securityfocus.com/bid/14047 vdb-entryx_refsource_BID
    Date Public
    2005-06-23 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T22:15:37.380Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "SUSE-SA:2005:038",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://www.novell.com/linux/security/advisories/2005_38_clamav.html"
              },
              {
                "name": "20050623 long sendmail timeouts let attacker prevent milter quiesce",
                "tags": [
                  "mailing-list",
                  "x_refsource_BUGTRAQ",
                  "x_transferred"
                ],
                "url": "http://seclists.org/lists/bugtraq/2005/Jun/0197.html"
              },
              {
                "name": "DSA-737",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2005/dsa-737"
              },
              {
                "name": "14047",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/14047"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2005-06-23T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a denial of service by keeping an open connection, which prevents ClamAV from reloading."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2005-07-07T09:00:00.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "SUSE-SA:2005:038",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://www.novell.com/linux/security/advisories/2005_38_clamav.html"
            },
            {
              "name": "20050623 long sendmail timeouts let attacker prevent milter quiesce",
              "tags": [
                "mailing-list",
                "x_refsource_BUGTRAQ"
              ],
              "url": "http://seclists.org/lists/bugtraq/2005/Jun/0197.html"
            },
            {
              "name": "DSA-737",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2005/dsa-737"
            },
            {
              "name": "14047",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/14047"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2005-2070",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a denial of service by keeping an open connection, which prevents ClamAV from reloading."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "SUSE-SA:2005:038",
                  "refsource": "SUSE",
                  "url": "http://www.novell.com/linux/security/advisories/2005_38_clamav.html"
                },
                {
                  "name": "20050623 long sendmail timeouts let attacker prevent milter quiesce",
                  "refsource": "BUGTRAQ",
                  "url": "http://seclists.org/lists/bugtraq/2005/Jun/0197.html"
                },
                {
                  "name": "DSA-737",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2005/dsa-737"
                },
                {
                  "name": "14047",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/14047"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2005-2070",
        "datePublished": "2005-06-29T04:00:00.000Z",
        "dateReserved": "2005-06-29T00:00:00.000Z",
        "dateUpdated": "2024-08-07T22:15:37.380Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2002-1827 (GCVE-0-2002-1827)

    Vulnerability from cvelistv5 – Published: 2005-06-28 04:00 – Updated: 2024-08-08 03:43
    VLAI
    Summary
    Sendmail 8.9.0 through 8.12.3 allows local users to cause a denial of service by obtaining an exclusive lock on the (1) alias, (2) map, (3) statistics, and (4) pid files.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Date Public
    2002-05-23 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-08T03:43:32.808Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "20020524 Sendmail file locking - PoC",
                "tags": [
                  "mailing-list",
                  "x_refsource_BUGTRAQ",
                  "x_transferred"
                ],
                "url": "http://online.securityfocus.com/archive/1/274033"
              },
              {
                "name": "sendmail-file-locking-dos(9162)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "http://www.iss.net/security_center/static/9162.php"
              },
              {
                "name": "4822",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/4822"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.sendmail.org/LockingAdvisory.txt"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2002-05-23T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Sendmail 8.9.0 through 8.12.3 allows local users to cause a denial of service by obtaining an exclusive lock on the (1) alias, (2) map, (3) statistics, and (4) pid files."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-06-15T16:39:18.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "20020524 Sendmail file locking - PoC",
              "tags": [
                "mailing-list",
                "x_refsource_BUGTRAQ"
              ],
              "url": "http://online.securityfocus.com/archive/1/274033"
            },
            {
              "name": "sendmail-file-locking-dos(9162)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "http://www.iss.net/security_center/static/9162.php"
            },
            {
              "name": "4822",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/4822"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.sendmail.org/LockingAdvisory.txt"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2002-1827",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Sendmail 8.9.0 through 8.12.3 allows local users to cause a denial of service by obtaining an exclusive lock on the (1) alias, (2) map, (3) statistics, and (4) pid files."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "20020524 Sendmail file locking - PoC",
                  "refsource": "BUGTRAQ",
                  "url": "http://online.securityfocus.com/archive/1/274033"
                },
                {
                  "name": "sendmail-file-locking-dos(9162)",
                  "refsource": "XF",
                  "url": "http://www.iss.net/security_center/static/9162.php"
                },
                {
                  "name": "4822",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/4822"
                },
                {
                  "name": "http://www.sendmail.org/LockingAdvisory.txt",
                  "refsource": "CONFIRM",
                  "url": "http://www.sendmail.org/LockingAdvisory.txt"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2002-1827",
        "datePublished": "2005-06-28T04:00:00.000Z",
        "dateReserved": "2005-06-29T00:00:00.000Z",
        "dateUpdated": "2024-08-08T03:43:32.808Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CERTA-2006-ALE-003

    Vulnerability from certfr_alerte - Published: 2006-03-24 - Updated: 2006-03-24

    Une vulnérabilité dans le logiciel de messagerie Sendmail permet à un utilisateur distant mal intentionné d'exécuter du code arbitraire à distance. Le fort déploiement de Sendmail combiné à la gravité de la faille a conduit le CERTA à augmenter le niveau de vigilence au niveau d'alerte, en plus de l'avis CERTA-2006-AVI-124 publié la jeudi 23 mars 2006.
    L'objectif de cette alerte est de sensibiliser les utilisateurs à la nécessité d'appliquer les correctifs en fonction des systèmes concernés.

    Description

    Sendmail est un logiciel de routage de messages électroniques (Mail Transport Agent ou MTA).
    Une vulnérabilité dans la gestion de messages asynchrones par le logiciel Sendmail permet à un utilisateur distant mal intentionné d'exécuter du code arbitraire à distance sur la machine vulnérable.

    Solution

    Mettre à jour Sendmail en version 8.13.6. En plus de ce problème de sécurité, Sendmail version 8.13.6 corrige d'autres problèmes de sécurité et d'autres faiblesses dans le code. Sendmail 8.13.6 peut se télécharger à l'adresse suivante :

    http://www.sendmail.org/8.13.6.html
    

    Si la mise à jour de Sendmail en version 8.13.6 n'est paspossible, appliquer les correctifs pour Sendmail 8.12.11 et 8.13.5.Les correctifs sont disponibles aux adresses suivantes :

    ftp://ftp.sendmail.org/pub/sendmail/8.12.11.p0
    
    ftp://ftp.sendmail.org/pub/sendmail/8.13.5.p0
    

    Dans tous les cas, se référer au bulletin de sécurité del'éditeur pour l'obtention des correctifs (cf. sectionDocumentation).

    None
    Impacted products
    Vendor Product Description
    Sendmail sendmail Pour la branche 8.12.x, Sendmail version 8.12.11 et versions antérieures ;
    Sendmail sendmail pour la branche 8.13.x, Sendmail version 8.13.5 et versions antérieures.
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Pour la branche 8.12.x, Sendmail version 8.12.11 et versions ant\u00e9rieures ;",
          "product": {
            "name": "sendmail",
            "vendor": {
              "name": "Sendmail",
              "scada": false
            }
          }
        },
        {
          "description": "pour la branche 8.13.x, Sendmail version 8.13.5 et versions ant\u00e9rieures.",
          "product": {
            "name": "sendmail",
            "vendor": {
              "name": "Sendmail",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "closed_at": "2006-03-24",
      "content": "## Description\n\nSendmail est un logiciel de routage de messages \u00e9lectroniques (Mail\nTransport Agent ou MTA).  \nUne vuln\u00e9rabilit\u00e9 dans la gestion de messages asynchrones par le\nlogiciel Sendmail permet \u00e0 un utilisateur distant mal intentionn\u00e9\nd\u0027ex\u00e9cuter du code arbitraire \u00e0 distance sur la machine vuln\u00e9rable.\n\n## Solution\n\nMettre \u00e0 jour Sendmail en version 8.13.6. En plus de ce probl\u00e8me de\ns\u00e9curit\u00e9, Sendmail version 8.13.6 corrige d\u0027autres probl\u00e8mes de s\u00e9curit\u00e9\net d\u0027autres faiblesses dans le code. Sendmail 8.13.6 peut se t\u00e9l\u00e9charger\n\u00e0 l\u0027adresse suivante :\n\n    http://www.sendmail.org/8.13.6.html\n\nSi la mise \u00e0 jour de Sendmail en version 8.13.6 n\u0027est paspossible,\nappliquer les correctifs pour Sendmail 8.12.11 et 8.13.5.Les correctifs\nsont disponibles aux adresses suivantes :\n\n    ftp://ftp.sendmail.org/pub/sendmail/8.12.11.p0\n\n    ftp://ftp.sendmail.org/pub/sendmail/8.13.5.p0\n\nDans tous les cas, se r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 del\u0027\u00e9diteur pour\nl\u0027obtention des correctifs (cf. sectionDocumentation).\n",
      "cves": [
        {
          "name": "CVE-2006-0058",
          "url": "https://www.cve.org/CVERecord?id=CVE-2006-0058"
        }
      ],
      "initial_release_date": "2006-03-24T00:00:00",
      "last_revision_date": "2006-03-24T00:00:00",
      "links": [
        {
          "title": "Mises \u00e0 jour de s\u00e9curit\u00e9 pour Fedora du 22 mars 2006 :",
          "url": "http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 Debian DSA-1015 du 23 mars 2006 :",
          "url": "http://www.debian.org/security/2006/dsa-1015"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 Gentoo GLSA-200603-21 du 22 mars 2006    :",
          "url": "http://www.gentoo.org/security/en/glsa/glsa-200603-21.xml"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 Mandriva MDKSA-2006:058 du 22 mars    2006 :",
          "url": "http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:058"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 ISS du 22 mars 2006 :",
          "url": "http://xforce.iss.net/xforce/alerts/id/216"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 IBM AIX du 23 mars 2006 :",
          "url": "http://www-1.ibm.com/support/docview.wss?uid=isg1IY82992"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 IBM AIX du 23 mars 2006 :",
          "url": "http://www-1.ibm.com/support/docview.wss?uid=isg1IY82994"
        },
        {
          "title": "Site Internet de Sendmail :",
          "url": "http://www.sendmail.com"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 RedHat RHSA-2006:0265 du 22 mars 2006    :",
          "url": "http://rhn.redhat.com/errata/RHSA-2006-0265.html"
        },
        {
          "title": "Alerte de s\u00e9curit\u00e9 de l\u0027US-CERT TA06-081A et VU#834865 du    22 mars 2006 :",
          "url": "http://www.us-cert.gov/cas/techalerts/TA06-081A.html"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 RedHat RHSA-2006:0264 du 22 mars 2006    :",
          "url": "http://rhn.redhat.com/errata/RHSA-2006-0264.html"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 IBM AIX du 23 mars 2006 :",
          "url": "http://www-1.ibm.com/support/docview.wss?uid=isg1IY82993"
        },
        {
          "title": "Page Internet de la version 8.13.6 de Sendmail :",
          "url": "http://www.sendmail.org/8.13.6.html"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 CERTA-2006-AVI-124 du jeudi 23 mars    2006 :",
          "url": "http://www.certa.ssi.gouv.fr/site/CERTA-2006-AVI-124/index.html"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 FreeBSD SA-06:13.sendmail du 22 mars    2006 :",
          "url": "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:13.sendmail.asc"
        },
        {
          "title": "Alerte de s\u00e9curit\u00e9 de l\u0027US-CERT TA06-081A et VU#834865 du    22 mars 2006 :",
          "url": "http://www.kb.cert.org/vuls/id/834865"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 Sendmail du 22 mars 2006 :",
          "url": "http://www.sendmail.com/company/advisory/index.shtml"
        },
        {
          "title": "Mises \u00e0 jour de s\u00e9curit\u00e9 pour Fedora du 22 mars 2006 :",
          "url": "http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 Sun Alerte #102262 du 22 mars 2006 :",
          "url": "http://sunsolve.sun.com/search/document.do?assetKey=1-26-102262-1"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 Slackware SSA:2006-081-01 du 22 mars    2003 :",
          "url": "http://slackware.com/security/viewer.php?l=slackware-security\u0026y=2006\u0026m=slackware-security.619600"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SuSE-SA:2006:017 du 22 mars 2006    :",
          "url": "http://www.novell.com/linux/security/advisories/2006_17_sendmail.html"
        }
      ],
      "reference": "CERTA-2006-ALE-003",
      "revisions": [
        {
          "description": "version initiale.",
          "revision_date": "2006-03-24T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 dans le logiciel de messagerie Sendmail permet \u00e0 un\nutilisateur distant mal intentionn\u00e9 d\u0027ex\u00e9cuter du code arbitraire \u00e0\ndistance. Le fort d\u00e9ploiement de Sendmail combin\u00e9 \u00e0 la gravit\u00e9 de la\nfaille a conduit le CERTA \u00e0 augmenter le niveau de vigilence au niveau\nd\u0027alerte, en plus de l\u0027avis CERTA-2006-AVI-124 publi\u00e9 la jeudi 23 mars\n2006.  \n\u003cspan class=\"textbf\"\u003eL\u0027objectif de cette alerte est de sensibiliser les\nutilisateurs \u00e0 la n\u00e9cessit\u00e9 d\u0027appliquer les correctifs en fonction des\nsyst\u00e8mes concern\u00e9s\u003c/span\u003e.\n",
      "title": "Vuln\u00e9rabilit\u00e9 de Sendmail",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 du CERTA CERTA-2006-AVI-124 du 23 mars 2006",
          "url": null
        }
      ]
    }

    CERTA-2006-AVI-124

    Vulnerability from certfr_avis - Published: 2006-03-23 - Updated: 2006-06-23

    Une vulnérabilité dans le logiciel de messagerie Sendmail permet à un utilisateur distant mal intentionné d'exécuter du code arbitraire à distance.

    Description

    Sendmail est un logiciel de routage de messages électroniques (Mail Transport Agent ou MTA).
    Une vulnérabilité dans la gestion de messages asynchrones par le logiciel Sendmail permet à un utilisateur distant mal intentionné d'exécuter du code arbitraire à distance sur la machine vulnérable.

    Solution

    Mettre à jour Sendmail en version 8.13.6. En plus de ce problème de sécurité, Sendmail version 8.13.6 corrige d'autres problèmes de sécurité et d'autres faiblesses dans le code. Sendmail 8.13.6 peut se télécharger à l'adresse suivante :

    http://www.sendmail.org/8.13.6.html
    

    Si la mise à jour de Sendmail en version 8.13.6 n'est paspossible, appliquer les correctifs pour Sendmail 8.12.11 et 8.13.5.Les correctifs sont disponibles aux adresses suivantes :

    ftp://ftp.sendmail.org/pub/sendmail/8.12.11.p0
    
    ftp://ftp.sendmail.org/pub/sendmail/8.13.5.p0
    

    Dans tous les cas, se référer au bulletin de sécurité del'éditeur pour l'obtention des correctifs (cf. sectionDocumentation).

    None
    Impacted products
    Vendor Product Description
    Sendmail sendmail Pour la branche 8.12.x, Sendmail version 8.12.11 et versions antérieures ;
    Sendmail sendmail pour la branche 8.13.x, Sendmail version 8.13.5 et versions antérieures.
    References
    Bulletin de sécurité Sendmail du 22 mars 2006 None vendor-advisory
    Mises à jour de sécurité pour Fedora du 22 mars 2006 : - other
    Bulletin de sécurité Avaya ASA-2006-078 du 12 avril 2006 : - other
    Bulletin de sécurité Debian DSA-1015 du 23 mars 2006 : - other
    Bulletin de sécurité Gentoo GLSA-200603-21 du 22 mars 2006 : - other
    Bulletin de sécurité Mandriva MDKSA-2006:058 du 22 mars 2006 : - other
    Bulletin de sécurité OpenBSD 3.8 et OpenBSD 3.9 pour sendmail du 25 mars 2006 : - other
    Bulletin de sécurité ISS du 22 mars 2006 : - other
    Bulletin de sécurité IBM AIX du 23 mars 2006 : - other
    Bulletin de sécurité Avaya ASA-2006-074 du 24 mars 2006 : - other
    Bulletin de sécurité IBM AIX du 23 mars 2006 : - other
    Site Internet de Sendmail : - other
    Bulletin de sécurité RedHat RHSA-2006:0265 du 22 mars 2006 : - other
    Bulletin de sécurité de SGI du 4 avril 2006 : - other
    Alerte de sécurité de l'US-CERT TA06-081A et VU#834865 du 22 mars 2006 : - other
    Bulletin de sécurité HP-UX #c00629555 (HPSBUX02108 SSRT061133) du 25 mars 2006 : - other
    Bulletin de sécurité OpenBSD 3.8 et OpenBSD 3.9 pour sendmail du 25 mars 2006 : - other
    Bulletin de sécurité RedHat RHSA-2006:0264 du 22 mars 2006 : - other
    Bulletin de sécurité IBM AIX du 23 mars 2006 : - other
    Page Internet de la version 8.13.6 de Sendmail : - other
    Bulletin de sécurité IBM : - other
    Bulletin de sécurité FreeBSD SA-06:13.sendmail du 22 mars 2006 : - other
    Alerte de sécurité de l'US-CERT TA06-081A et VU#834865 du 22 mars 2006 : - other
    Mises à jour de sécurité pour Fedora du 22 mars 2006 : - other
    Bulletin de sécurité Sun Alerte #102262 du 22 mars 2006 : - other
    Bulletin de sécurité Slackware SSA:2006-081-01 du 22 mars 2003 : - other
    Bulletin de sécurité SUSE SuSE-SA:2006:017 du 22 mars 2006 : - other

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Pour la branche 8.12.x, Sendmail version 8.12.11 et versions ant\u00e9rieures ;",
          "product": {
            "name": "sendmail",
            "vendor": {
              "name": "Sendmail",
              "scada": false
            }
          }
        },
        {
          "description": "pour la branche 8.13.x, Sendmail version 8.13.5 et versions ant\u00e9rieures.",
          "product": {
            "name": "sendmail",
            "vendor": {
              "name": "Sendmail",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Description\n\nSendmail est un logiciel de routage de messages \u00e9lectroniques (Mail\nTransport Agent ou MTA).  \nUne vuln\u00e9rabilit\u00e9 dans la gestion de messages asynchrones par le\nlogiciel Sendmail permet \u00e0 un utilisateur distant mal intentionn\u00e9\nd\u0027ex\u00e9cuter du code arbitraire \u00e0 distance sur la machine vuln\u00e9rable.\n\n## Solution\n\nMettre \u00e0 jour Sendmail en version 8.13.6. En plus de ce probl\u00e8me de\ns\u00e9curit\u00e9, Sendmail version 8.13.6 corrige d\u0027autres probl\u00e8mes de s\u00e9curit\u00e9\net d\u0027autres faiblesses dans le code. Sendmail 8.13.6 peut se t\u00e9l\u00e9charger\n\u00e0 l\u0027adresse suivante :\n\n    http://www.sendmail.org/8.13.6.html\n\nSi la mise \u00e0 jour de Sendmail en version 8.13.6 n\u0027est paspossible,\nappliquer les correctifs pour Sendmail 8.12.11 et 8.13.5.Les correctifs\nsont disponibles aux adresses suivantes :\n\n    ftp://ftp.sendmail.org/pub/sendmail/8.12.11.p0\n\n    ftp://ftp.sendmail.org/pub/sendmail/8.13.5.p0\n\nDans tous les cas, se r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 del\u0027\u00e9diteur pour\nl\u0027obtention des correctifs (cf. sectionDocumentation).\n",
      "cves": [
        {
          "name": "CVE-2006-0058",
          "url": "https://www.cve.org/CVERecord?id=CVE-2006-0058"
        }
      ],
      "initial_release_date": "2006-03-23T00:00:00",
      "last_revision_date": "2006-06-23T00:00:00",
      "links": [
        {
          "title": "Mises \u00e0 jour de s\u00e9curit\u00e9 pour Fedora du 22 mars 2006 :",
          "url": "http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 Avaya ASA-2006-078 du 12 avril 2006 :",
          "url": "http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 Debian DSA-1015 du 23 mars 2006 :",
          "url": "http://www.debian.org/security/2006/dsa-1015"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 Gentoo GLSA-200603-21 du 22 mars 2006    :",
          "url": "http://www.gentoo.org/security/en/glsa/glsa-200603-21.xml"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 Mandriva MDKSA-2006:058 du 22 mars    2006 :",
          "url": "http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:058"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 OpenBSD 3.8 et OpenBSD 3.9 pour    sendmail du 25 mars 2006 :",
          "url": "http://www.openbsd.org/errata38.html#sendmail"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 ISS du 22 mars 2006 :",
          "url": "http://xforce.iss.net/xforce/alerts/id/216"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 IBM AIX du 23 mars 2006 :",
          "url": "http://www-1.ibm.com/support/docview.wss?uid=isg1IY82992"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 Avaya ASA-2006-074 du 24 mars 2006 :",
          "url": "http://support.avaya.com/elmodocs2/security/ASA-2006-074.htm"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 IBM AIX du 23 mars 2006 :",
          "url": "http://www-1.ibm.com/support/docview.wss?uid=isg1IY82994"
        },
        {
          "title": "Site Internet de Sendmail :",
          "url": "http://www.sendmail.com"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 RedHat RHSA-2006:0265 du 22 mars 2006    :",
          "url": "http://rhn.redhat.com/errata/RHSA-2006-0265.html"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 de SGI du 4 avril 2006 :",
          "url": "ftp://patches.sgi.com/support/free/security/advisories/20060302-01-P.asc"
        },
        {
          "title": "Alerte de s\u00e9curit\u00e9 de l\u0027US-CERT TA06-081A et VU#834865 du    22 mars 2006 :",
          "url": "http://www.us-cert.gov/cas/techalerts/TA06-081A.html"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 HP-UX #c00629555 (HPSBUX02108    SSRT061133) du 25 mars 2006 :",
          "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00629555"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 OpenBSD 3.8 et OpenBSD 3.9 pour    sendmail du 25 mars 2006 :",
          "url": "http://www.openbsd.org/errata.html#sendmail"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 RedHat RHSA-2006:0264 du 22 mars 2006    :",
          "url": "http://rhn.redhat.com/errata/RHSA-2006-0264.html"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 IBM AIX du 23 mars 2006 :",
          "url": "http://www-1.ibm.com/support/docview.wss?uid=isg1IY82993"
        },
        {
          "title": "Page Internet de la version 8.13.6 de Sendmail :",
          "url": "http://www.sendmail.org/8.13.6.html"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 IBM :",
          "url": "http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 FreeBSD SA-06:13.sendmail du 22 mars    2006 :",
          "url": "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:13.sendmail.asc"
        },
        {
          "title": "Alerte de s\u00e9curit\u00e9 de l\u0027US-CERT TA06-081A et VU#834865 du    22 mars 2006 :",
          "url": "http://www.kb.cert.org/vuls/id/834865"
        },
        {
          "title": "Mises \u00e0 jour de s\u00e9curit\u00e9 pour Fedora du 22 mars 2006 :",
          "url": "http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 Sun Alerte #102262 du 22 mars 2006 :",
          "url": "http://sunsolve.sun.com/search/document.do?assetKey=1-26-102262-1"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 Slackware SSA:2006-081-01 du 22 mars    2003 :",
          "url": "http://slackware.com/security/viewer.php?l=slackware-security\u0026y=2006\u0026m=slackware-security.619600"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 SUSE SuSE-SA:2006:017 du 22 mars 2006    :",
          "url": "http://www.novell.com/linux/security/advisories/2006_17_sendmail.html"
        }
      ],
      "reference": "CERTA-2006-AVI-124",
      "revisions": [
        {
          "description": "version initiale.",
          "revision_date": "2006-03-23T00:00:00.000000"
        },
        {
          "description": "ajout de la r\u00e9f\u00e9rence au bulletin de s\u00e9curit\u00e9 OpenBSD et Avaya.",
          "revision_date": "2006-03-27T00:00:00.000000"
        },
        {
          "description": "ajout de la r\u00e9f\u00e9rence au bulletin de s\u00e9curit\u00e9 SGI IRIX.",
          "revision_date": "2006-04-05T00:00:00.000000"
        },
        {
          "description": "ajout de la r\u00e9f\u00e9rence au bulletin de s\u00e9curit\u00e9 Avaya.",
          "revision_date": "2006-04-18T00:00:00.000000"
        },
        {
          "description": "ajout de la r\u00e9f\u00e9rence au bulletin de s\u00e9curit\u00e9 IBM.",
          "revision_date": "2006-06-23T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 dans le logiciel de messagerie Sendmail permet \u00e0 un\nutilisateur distant mal intentionn\u00e9 d\u0027ex\u00e9cuter du code arbitraire \u00e0\ndistance.\n",
      "title": "Vuln\u00e9rabilit\u00e9 de Sendmail",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 Sendmail du 22 mars 2006",
          "url": "http://www.sendmail.com/company/advisory/index.shtml"
        }
      ]
    }