Vulnerability Description
Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sendmail | Sendmail | < 8.13.8 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/21637Broken LinkPatchVendor Advisory
- http://secunia.com/advisories/21641Broken LinkPatchVendor Advisory
- http://secunia.com/advisories/21696Broken LinkVendor Advisory
- http://secunia.com/advisories/21700Broken LinkVendor Advisory
- http://secunia.com/advisories/21749Broken LinkVendor Advisory
- http://secunia.com/advisories/22369Broken LinkVendor Advisory
- http://securitytracker.com/id?1016753Broken LinkPatchThird Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102664-1Broken Link
- http://www.attrition.org/pipermail/vim/2006-August/000999.htmlMailing List
- http://www.debian.org/security/2006/dsa-1164Broken Link
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:156Broken Link
- http://www.novell.com/linux/security/advisories/2006_21_sr.htmlBroken Link
- http://www.openbsd.org/errata.html#sendmail3Release Notes
- http://www.openbsd.org/errata38.html#sendmail3Third Party Advisory
- http://www.osvdb.org/28193Broken Link
FAQ
What is CVE-2006-4434?
CVE-2006-4434 is a vulnerability with a CVSS score of 7.5 (HIGH). Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced....
How severe is CVE-2006-4434?
CVE-2006-4434 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-4434?
Check the references section above for vendor advisories and patch information. Affected products include: Sendmail Sendmail.