CVE-2006-4434
Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.46%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected."
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 4.46% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- sendmail/sendmail
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/21637Broken Link, Patch, Vendor Advisory
- http://secunia.com/advisories/21641Broken Link, Patch, Vendor Advisory
- http://secunia.com/advisories/21696Broken Link, Vendor Advisory
- http://secunia.com/advisories/21700Broken Link, Vendor Advisory
- http://secunia.com/advisories/21749Broken Link, Vendor Advisory
- http://secunia.com/advisories/22369Broken Link, Vendor Advisory
- http://securitytracker.com/id?1016753Broken Link, Patch, Third Party Advisory, VDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102664-1Broken Link
- http://www.attrition.org/pipermail/vim/2006-August/000999.htmlMailing List
- http://www.debian.org/security/2006/dsa-1164Broken Link
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:156Broken Link
- http://www.novell.com/linux/security/advisories/2006_21_sr.htmlBroken Link
- http://www.openbsd.org/errata.html#sendmail3Release Notes
- http://www.openbsd.org/errata38.html#sendmail3Third Party Advisory
- http://www.osvdb.org/28193Broken Link
- http://www.securityfocus.com/bid/19714Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.sendmail.org/releases/8.13.8.htmlRelease Notes
- http://www.vupen.com/english/advisories/2006/3393Broken Link, Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3994Broken Link, Vendor Advisory
- http://secunia.com/advisories/21637Broken Link, Patch, Vendor Advisory
- http://secunia.com/advisories/21641Broken Link, Patch, Vendor Advisory
- http://secunia.com/advisories/21696Broken Link, Vendor Advisory
- http://secunia.com/advisories/21700Broken Link, Vendor Advisory
- http://secunia.com/advisories/21749Broken Link, Vendor Advisory
- http://secunia.com/advisories/22369Broken Link, Vendor Advisory
- http://securitytracker.com/id?1016753Broken Link, Patch, Third Party Advisory, VDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102664-1Broken Link
- http://www.attrition.org/pipermail/vim/2006-August/000999.htmlMailing List
- http://www.debian.org/security/2006/dsa-1164Broken Link
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:156Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.