CVE-2006-1173
Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents…
Does this matter?
Lower severity and a low EPSS score (5.27%). Track it; it rarely justifies an emergency change on its own.
Description
Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 5.27% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- sendmail/sendmail
- Source
- cret@cert.org
References
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:17.sendmail.asc
- ftp://patches.sgi.com/support/free/security/advisories/20060601-01-P
- ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc
- http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635
- http://lists.suse.com/archive/suse-security-announce/2006-Jun/0006.html
- http://secunia.com/advisories/15779Patch, Vendor Advisory
- http://secunia.com/advisories/20473Patch, Vendor Advisory
- http://secunia.com/advisories/20641Vendor Advisory
- http://secunia.com/advisories/20650Vendor Advisory
- http://secunia.com/advisories/20651Vendor Advisory
- http://secunia.com/advisories/20654Vendor Advisory
- http://secunia.com/advisories/20673Vendor Advisory
- http://secunia.com/advisories/20675Vendor Advisory
- http://secunia.com/advisories/20679Vendor Advisory
- http://secunia.com/advisories/20683Vendor Advisory
- http://secunia.com/advisories/20684Vendor Advisory
- http://secunia.com/advisories/20694Vendor Advisory
- http://secunia.com/advisories/20726Vendor Advisory
- http://secunia.com/advisories/20782Vendor Advisory
- http://secunia.com/advisories/21042Vendor Advisory
- http://secunia.com/advisories/21160Vendor Advisory
- http://secunia.com/advisories/21327Vendor Advisory
- http://secunia.com/advisories/21612Vendor Advisory
- http://secunia.com/advisories/21647Vendor Advisory
- http://securitytracker.com/id?1016295
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.631382
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102460-1Patch, Vendor Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2006-148.htm
- http://www-1.ibm.com/support/search.wss?rs=0&q=IY85415&apar=only
- http://www-1.ibm.com/support/search.wss?rs=0&q=IY85930&apar=only
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.