SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#146718

Sendmail fails to handle malformed multipart MIME messages

Overview

Sendmail does not properly handle malformed multipart MIME messages. This vulnerability may allow a remote, unauthenticated attacker to cause a denial-of-service condition.

I. Description

Sendmail

Sendmail is a widely used mail transfer agent (MTA).

Mail Transfer Agents (MTA)


MTAs are responsible for sending an receiving email messages over the internet. They are also referred to as mail servers or SMTP servers.

The Problem

Sendmail fails to properly handle malformed mulitpart MIME messages. This vulnerability may be triggered by sending a specially crafted message to a vulnerable Sendmail MTA.

II. Impact

This vulnerability will not cause the Sendmail server process to terminate. However, it may cause the Sendmail to consume a large amount of system resources. Specifically, if a system writes uniquely named core dump files, this vulnerability may cause available disk space to be filled with core dumps leading to a disruption of system operation resulting in a denial-of-service condition.

Additionally, this vulnerability may cause queue runs to abort; if this situation were to occur, processing and delivery of queued messages would be prevented.

III. Solution

Upgrade Sendmail

This issue is corrected in Sendmail version 8.13.7.

The following workarounds were provided by Sendmail:

Limit message size

Limiting the maximum message size accepted by your server (via the sendmail MaxMessageSize option) will mitigate this vulnerability.

Remove stack size limit

If your operating system limits stack size, remove that limit. This will make the attack more difficult to accomplish, as it will require a very large message. Also, by limiting the maximum message size accepted by your server (via the sendmail MaxMessageSize option), you can eliminate the attack completely.

Configure your MTA to avoid the negative impacts listed above:

  • Disable core dumps.
  • Enable the ForkEachJob option at the cost of lower queue run performance and potentially a high number of processes.
  • Set QueueSortOrder to random, which will randomize the order jobs are processed. Note that with random queue sorting, the bad message will still be processed and the queue run aborted every time, but at a different, random spot.

Systems Affected

VendorStatusDate Updated
3com, Inc.Unknown10-May-2006
AlcatelUnknown10-May-2006
Apple Computer, Inc.Unknown10-May-2006
AT&TUnknown10-May-2006
Avaya, Inc.Unknown10-May-2006
Avici Systems, Inc.Unknown10-May-2006
Borderware TechnologiesNot Vulnerable26-May-2006
B.U.G., IncNot Vulnerable14-Jun-2006
Century Systems Inc.Not Vulnerable14-Jun-2006
Charlotte's Web NetworksUnknown10-May-2006
Check Point Software TechnologiesNot Vulnerable27-Jun-2006
Chiaro Networks, Inc.Unknown10-May-2006
Cisco Systems, Inc.Unknown10-May-2006
Computer AssociatesUnknown10-May-2006
Conectiva Inc.Unknown10-May-2006
Cray Inc.Unknown10-May-2006
D-Link Systems, Inc.Unknown10-May-2006
Data Connection, Ltd.Unknown10-May-2006
Debian GNU/LinuxUnknown10-May-2006
DragonFly BSD ProjectUnknown10-May-2006
EMC, Inc. (formerly Data General Corporation)Unknown10-May-2006
Engarde Secure LinuxUnknown10-May-2006
EricssonUnknown10-May-2006
eSoft, Inc.Unknown10-May-2006
Extreme NetworksUnknown10-May-2006
F5 Networks, Inc.Not Vulnerable16-May-2006
Fedora ProjectUnknown10-May-2006
Force10 Networks, Inc.Unknown10-May-2006
Fortinet, Inc.Unknown10-May-2006
Foundry Networks, Inc.Not Vulnerable15-Jun-2006
FreeBSD, Inc.Vulnerable15-Jun-2006
FujitsuNot Vulnerable15-Jun-2006
Gentoo LinuxVulnerable16-Jun-2006
Global Technology AssociatesNot Vulnerable27-Jun-2006
GNU netfilterUnknown10-May-2006
Hewlett-Packard CompanyUnknown10-May-2006
HitachiNot Vulnerable15-Jun-2006
HyperchipUnknown10-May-2006
IBM CorporationVulnerable15-Jun-2006
IBM Corporation (zseries)Unknown10-May-2006
IBM eServerUnknown10-May-2006
Immunix Communications, Inc.Unknown10-May-2006
Ingrian Networks, Inc.Unknown10-May-2006
Intel CorporationUnknown10-May-2006
Internet Initiative JapanNot Vulnerable14-Jun-2006
Internet Security Systems, Inc.Unknown10-May-2006
IntotoNot Vulnerable10-May-2006
IP FilterUnknown10-May-2006
Juniper Networks, Inc.Unknown10-May-2006
Justsystem CorporationNot Vulnerable14-Jun-2006
Linksys (A division of Cisco Systems)Unknown10-May-2006
Lotus SoftwareNot Vulnerable11-May-2006
Lucent TechnologiesUnknown10-May-2006
Luminous NetworksUnknown10-May-2006
Mandriva, Inc.Unknown10-May-2006
Microsoft CorporationUnknown10-May-2006
Mirapoint, Inc.Not Vulnerable15-Jul-2006
MontaVista Software, Inc.Unknown10-May-2006
Multinet (owned Process Software Corporation)Unknown10-May-2006
Multitech, Inc.Unknown10-May-2006
NEC CorporationNot Vulnerable15-Jun-2006
NetBSDVulnerable15-Jun-2006
Network Appliance, Inc.Not Vulnerable13-May-2006
NextHop Technologies, Inc.Unknown10-May-2006
NokiaUnknown10-May-2006
Nortel Networks, Inc.Not Vulnerable17-Jun-2006
Novell, Inc.Unknown10-May-2006
OpenBSDUnknown8-Jun-2006
Openwall GNU/*/LinuxNot Vulnerable10-May-2006
Oracle CorporationNot Vulnerable16-May-2006
QNX, Software Systems, Inc.Unknown10-May-2006
Red Hat, Inc.Vulnerable14-Jun-2006
Redback Networks, Inc.Not Vulnerable9-Jun-2006
Riverstone Networks, Inc.Unknown10-May-2006
Secure Computing Network Security DivisionNot Vulnerable22-Jun-2006
Secureworx, Inc.Unknown31-May-2006
Sendmail ConsortiumVulnerable15-Jun-2006
Sendmail, Inc.Vulnerable15-Jun-2006
Silicon Graphics, Inc.Unknown10-May-2006
Slackware Linux Inc.Unknown10-May-2006
Sony CorporationUnknown10-May-2006
StonesoftUnknown13-May-2006
Sun Microsystems, Inc.Vulnerable14-Jun-2006
SUSE LinuxUnknown10-May-2006
Symantec, Inc.Unknown10-May-2006
SyntegraNot Vulnerable15-Jun-2006
The SCO GroupUnknown15-Jun-2006
The SCO Group (SCO Unix)Unknown28-May-2006
Trustix Secure LinuxUnknown10-May-2006
TurbolinuxUnknown10-May-2006
UbuntuUnknown10-May-2006
UnisysUnknown10-May-2006
Watchguard Technologies, Inc.Unknown10-May-2006
Wind River Systems, Inc.Unknown10-May-2006
Yamaha CorporationNot Vulnerable14-Jun-2006
Yokogawa Electric CorporationNot Vulnerable14-Jun-2006
ZyXELUnknown10-May-2006

References


http://www.sendmail.com/security/advisories/SA-200605-01.txt.asc
http://www.sendmail.org/releases/8.13.7.html
http://www.sendmail.org/releases/8.13.7.html#RS
http://jvn.jp/cert/JVNVU%23146718/index.html
http://secunia.com/advisories/20473/
http://secunia.com/advisories/15779/
http://secunia.com/advisories/20641/
http://secunia.com/advisories/20673/
http://secunia.com/advisories/20650/
http://secunia.com/advisories/20654/
http://secunia.com/advisories/20651/
http://secunia.com/advisories/20683/

Credit

This vulnerability was reported by Sendmail.

This document was written by Jeff Gennari based on information from Sendmail.

Other Information

Date Public06/14/2006
Date First Published06/15/2006 07:09:51 AM
Date Last Updated10/03/2006
CERT Advisory 
CVE NameCVE-2006-1173
US-CERT Technical Alerts 
Metric13.51
Document Revision41

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2006 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader