SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information

Report a Vulnerability

 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#834865

Sendmail signal I/O race condition

Overview

A race condition in Sendmail may allow a remote attacker to execute arbitrary code.

I. Description

Sendmail

Sendmail is a widely used mail transfer agent (MTA).

Mail Transfer Agents (MTA)

MTAs are responsible for sending an receiving email messages over the internet. They are also referred to as mail servers or SMTP servers.

The Problem

Sendmail contains a race condition caused by the improper handling of asynchronous signals. In particular, by forcing SMTP server to have an I/O timeout at exactly the correct instant, the attacker may be able to execute arbitrary code with the privileges of the Sendmail process.

More information is available in the Sendmail version 8.13.6 release page and the Sendmail MTA Security Vulnerability Advisory.

This vulnerability occurred as a result of failing to comply with recommndations SIG32-C and SIG30-C of the CERT C Programming Language Secure Coding Standard.

Considerations

Versions of Sendmail prior to 8.13.6 are affected.

II. Impact

A remote, unauthenticated attacker could execute arbitrary code with the privileges of the Sendmail process. If Sendmail is running as root, the attacker could take complete control of an affected system.

III. Solution

Upgrade

This issue is corrected in Sendmail version 8.13.6.

Patches to correct this issue in Sendmail versions 8.12.11 and 8.13.5 are also available.

Refer to the Sendmail MTA Security Vulnerability Advisory for steps to reduce the impact of this vulnerability

Systems Affected

VendorStatusDate NotifiedDate Updated
3com, Inc.Unknown2006-03-082006-03-08
AlcatelUnknown2006-03-082006-03-08
Apple Computer, Inc.Not Vulnerable2006-03-082006-03-22
AT&TUnknown2006-03-082006-03-08
Avaya, Inc.Not Vulnerable2006-03-082006-03-09
Avici Systems, Inc.Unknown2006-03-082006-03-08
Borderware TechnologiesNot Vulnerable2006-03-082006-03-21
Charlotte's Web NetworksUnknown2006-03-082006-03-08
Check Point Software TechnologiesNot Vulnerable2006-03-082006-03-09
Chiaro Networks, Inc.Unknown2006-03-082006-03-08
Cisco Systems, Inc.Unknown2006-03-082006-03-16
Computer AssociatesUnknown2006-03-082006-03-08
Conectiva Inc.Unknown2006-03-092006-03-09
Cray Inc.Unknown2006-03-092006-03-09
D-Link Systems, Inc.Unknown2006-03-082006-03-08
Data Connection, Ltd.Unknown2006-03-082006-03-08
Debian GNU/LinuxUnknown2006-03-092006-03-09
EMC, Inc. (formerly Data General Corporation)Unknown2006-03-082006-03-08
Engarde Secure LinuxUnknown2006-03-082006-03-08
EricssonUnknown2006-03-082006-03-08
eSoft, Inc.Unknown2006-03-082006-03-08
Extreme NetworksUnknown2006-03-082006-03-08
F5 Networks, Inc.Not Vulnerable2006-03-082006-03-22
Fedora ProjectVulnerable2006-03-082006-03-21
Force10 Networks, Inc.Not Affected2006-03-082011-07-22
Fortinet, Inc.Unknown2006-03-082006-03-08
Foundry Networks, Inc.Unknown2006-03-082006-03-08
FreeBSD, Inc.Vulnerable2006-03-082006-03-30
FujitsuUnknown2006-03-082006-03-08
Gentoo LinuxVulnerable2006-03-082006-03-22
Global Technology AssociatesUnknown2006-03-082006-03-08
GNU netfilterUnknown2006-03-082006-03-08
Hewlett-Packard CompanyVulnerable2006-03-082006-03-27
HitachiUnknown2006-03-082006-03-08
HyperchipUnknown2006-03-082006-03-08
IBM CorporationVulnerable2006-03-152006-03-22
IBM Corporation (zseries)Unknown2006-03-082006-03-08
IBM eServerUnknown2006-03-082006-03-23
Immunix Communications, Inc.Unknown2006-03-082006-03-08
Ingrian Networks, Inc.Unknown2006-03-082006-03-08
Intel CorporationUnknown2006-03-082006-03-08
Internet Security Systems, Inc.Not Vulnerable2006-03-062006-03-23
IntotoNot Vulnerable2006-03-082006-03-09
IP FilterUnknown2006-03-082006-03-08
Juniper Networks, Inc.Not Vulnerable2006-03-082006-03-22
Linksys (A division of Cisco Systems)Unknown2006-03-082006-03-08
Lotus SoftwareNot Vulnerable2006-03-082006-03-21
Lucent TechnologiesUnknown2006-03-082006-03-08
Luminous NetworksUnknown2006-03-082006-03-08
Mandriva, Inc.Unknown2006-03-082006-03-08
Microsoft CorporationUnknown2006-03-082006-03-08
Mirapoint, Inc.Not Vulnerable2006-03-082006-03-23
MontaVista Software, Inc.Unknown2006-03-082006-03-08
Multinet (owned Process Software Corporation)Unknown2006-03-082006-03-08
Multitech, Inc.Unknown2006-03-082006-03-08
NEC CorporationNot Vulnerable2006-03-082006-03-22
NetBSDVulnerable2006-03-082006-04-03
Network Appliance, Inc.Unknown2006-03-082006-03-08
NextHop Technologies, Inc.Unknown2006-03-082006-03-08
NokiaUnknown2006-03-212006-03-21
Nortel Networks, Inc.Not Vulnerable2006-03-082006-03-23
Novell, Inc.Unknown2006-03-082006-03-08
OpenBSDVulnerable2006-03-212006-03-27
Openwall GNU/*/LinuxNot Vulnerable2006-03-082006-03-09
Oracle CorporationUnknown2006-03-082006-03-08
QNX, Software Systems, Inc.Unknown2006-03-082006-03-08
Red Hat, Inc.Vulnerable2006-03-082006-03-21
Redback Networks, Inc.Unknown2006-03-082006-03-08
Riverstone Networks, Inc.Unknown2006-03-082006-03-08
Secure Computing Network Security DivisionNot Vulnerable2006-03-082006-03-20
Sendmail.orgVulnerable2006-02-272006-03-21
Silicon Graphics, Inc.Unknown2006-03-082006-03-08
Slackware Linux Inc.Vulnerable2006-03-082006-03-24
Sony CorporationUnknown2006-03-082006-03-08
Sun Microsystems, Inc.Vulnerable2006-03-082006-03-27
SUSE LinuxVulnerable2006-03-082006-03-21
Symantec, Inc.Not Vulnerable2006-03-082006-04-17
SyntegraUnknown2006-03-082006-03-08
Trustix Secure LinuxUnknown2006-03-082006-03-08
TurbolinuxVulnerable2006-03-082006-03-29
UbuntuVulnerable2006-03-082006-03-22
UnisysUnknown2006-03-082006-03-08
Watchguard Technologies, Inc.Unknown2006-03-082006-03-08
Wind River Systems, Inc.Unknown2006-03-082006-03-08
ZyXELUnknown2006-03-082006-03-08

References

https://www.securecoding.cert.org/confluence/x/lwAV
https://www.securecoding.cert.org/confluence/x/34At
http://www.sendmail.org/8.13.6.html
http://www.sendmail.com/company/advisory
ftp://ftp.sendmail.org/pub/sendmail/8.13.5.p0
ftp://ftp.sendmail.org/pub/sendmail/8.12.11.p0
http://xforce.iss.net/xforce/alerts/id/216

Credit

Thanks to Sendmail Inc. for reporting this vulnerability. Sendmail credits Internet Security Systems with providing information about this issue.

This document was written by Jeff Gennari.

Other Information

Date Public:2006-03-22
Date First Published:2006-03-22
Date Last Updated:2011-07-22
CERT Advisory: 
CVE-ID(s):CVE-2006-0058
NVD-ID(s):CVE-2006-0058
US-CERT Technical Alerts:TA06-081A
Severity Metric:19.88
Document Revision:91

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2006 by US-CERT, a government organization
Disclaimers and copyright information
Get a PDF Reader