SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#834865

Sendmail signal I/O race condition

Overview

A race condition in Sendmail may allow a remote attacker to execute arbitrary code.

I. Description

Sendmail

Sendmail is a widely used mail transfer agent (MTA).

Mail Transfer Agents (MTA)

MTAs are responsible for sending an receiving email messages over the internet. They are also referred to as mail servers or SMTP servers.

The Problem

Sendmail contains a race condition caused by the improper handling of asynchronous signals. In particular, by forcing SMTP server to have an I/O timeout at exactly the correct instant, the attacker may be able to execute arbitrary code with the privileges of the Sendmail process.

More information is available in the Sendmail version 8.13.6 release page and the Sendmail MTA Security Vulnerability Advisory.

This vulnerability occurred as a result of failing to comply with recommndations SIG32-C and SIG30-C of the CERT C Programming Language Secure Coding Standard.

Considerations

Versions of Sendmail prior to 8.13.6 are affected.

II. Impact

A remote, unauthenticated attacker could execute arbitrary code with the privileges of the Sendmail process. If Sendmail is running as root, the attacker could take complete control of an affected system.

III. Solution

Upgrade

This issue is corrected in Sendmail version 8.13.6.

Patches to correct this issue in Sendmail versions 8.12.11 and 8.13.5 are also available.

Refer to the Sendmail MTA Security Vulnerability Advisory for steps to reduce the impact of this vulnerability

Systems Affected

VendorStatusDate NotifiedDate Updated
3com, Inc.Unknown8-Mar-2006
AlcatelUnknown8-Mar-2006
Apple Computer, Inc.Not Vulnerable22-Mar-2006
AT&TUnknown8-Mar-2006
Avaya, Inc.Not Vulnerable9-Mar-2006
Avici Systems, Inc.Unknown8-Mar-2006
Borderware TechnologiesNot Vulnerable21-Mar-2006
Charlotte's Web NetworksUnknown8-Mar-2006
Check Point Software TechnologiesNot Vulnerable9-Mar-2006
Chiaro Networks, Inc.Unknown8-Mar-2006
Cisco Systems, Inc.Unknown16-Mar-2006
Computer AssociatesUnknown8-Mar-2006
Conectiva Inc.Unknown9-Mar-2006
Cray Inc.Unknown9-Mar-2006
D-Link Systems, Inc.Unknown8-Mar-2006
Data Connection, Ltd.Unknown8-Mar-2006
Debian GNU/LinuxUnknown9-Mar-2006
EMC, Inc. (formerly Data General Corporation)Unknown8-Mar-2006
Engarde Secure LinuxUnknown8-Mar-2006
EricssonUnknown8-Mar-2006
eSoft, Inc.Unknown8-Mar-2006
Extreme NetworksUnknown8-Mar-2006
F5 Networks, Inc.Not Vulnerable22-Mar-2006
Fedora ProjectVulnerable21-Mar-2006
Force10 Networks, Inc.Unknown8-Mar-2006
Fortinet, Inc.Unknown8-Mar-2006
Foundry Networks, Inc.Unknown8-Mar-2006
FreeBSD, Inc.Vulnerable30-Mar-2006
FujitsuUnknown8-Mar-2006
Gentoo LinuxVulnerable22-Mar-2006
Global Technology AssociatesUnknown8-Mar-2006
GNU netfilterUnknown8-Mar-2006
Hewlett-Packard CompanyVulnerable27-Mar-2006
HitachiUnknown8-Mar-2006
HyperchipUnknown8-Mar-2006
IBM CorporationVulnerable22-Mar-2006
IBM Corporation (zseries)Unknown8-Mar-2006
IBM eServerUnknown23-Mar-2006
Immunix Communications, Inc.Unknown8-Mar-2006
Ingrian Networks, Inc.Unknown8-Mar-2006
Intel CorporationUnknown8-Mar-2006
Internet Security Systems, Inc.Not Vulnerable23-Mar-2006
IntotoNot Vulnerable9-Mar-2006
IP FilterUnknown8-Mar-2006
Juniper Networks, Inc.Not Vulnerable22-Mar-2006
Linksys (A division of Cisco Systems)Unknown8-Mar-2006
Lotus SoftwareNot Vulnerable21-Mar-2006
Lucent TechnologiesUnknown8-Mar-2006
Luminous NetworksUnknown8-Mar-2006
Mandriva, Inc.Unknown8-Mar-2006
Microsoft CorporationUnknown8-Mar-2006
Mirapoint, Inc.Not Vulnerable23-Mar-2006
MontaVista Software, Inc.Unknown8-Mar-2006
Multinet (owned Process Software Corporation)Unknown8-Mar-2006
Multitech, Inc.Unknown8-Mar-2006
NEC CorporationNot Vulnerable22-Mar-2006
NetBSDVulnerable3-Apr-2006
Network Appliance, Inc.Unknown8-Mar-2006
NextHop Technologies, Inc.Unknown8-Mar-2006
NokiaUnknown21-Mar-2006
Nortel Networks, Inc.Not Vulnerable23-Mar-2006
Novell, Inc.Unknown8-Mar-2006
OpenBSDVulnerable27-Mar-2006
Openwall GNU/*/LinuxNot Vulnerable9-Mar-2006
Oracle CorporationUnknown8-Mar-2006
QNX, Software Systems, Inc.Unknown8-Mar-2006
Red Hat, Inc.Vulnerable21-Mar-2006
Redback Networks, Inc.Unknown8-Mar-2006
Riverstone Networks, Inc.Unknown8-Mar-2006
Secure Computing Network Security DivisionNot Vulnerable20-Mar-2006
Sendmail.orgVulnerable21-Mar-2006
Silicon Graphics, Inc.Unknown8-Mar-2006
Slackware Linux Inc.Vulnerable24-Mar-2006
Sony CorporationUnknown8-Mar-2006
Sun Microsystems, Inc.Vulnerable27-Mar-2006
SUSE LinuxVulnerable21-Mar-2006
Symantec, Inc.Not Vulnerable17-Apr-2006
SyntegraUnknown8-Mar-2006
Trustix Secure LinuxUnknown8-Mar-2006
TurbolinuxVulnerable29-Mar-2006
UbuntuVulnerable22-Mar-2006
UnisysUnknown8-Mar-2006
Watchguard Technologies, Inc.Unknown8-Mar-2006
Wind River Systems, Inc.Unknown8-Mar-2006
ZyXELUnknown8-Mar-2006

References

https://www.securecoding.cert.org/confluence/x/lwAV
https://www.securecoding.cert.org/confluence/x/34At
http://www.sendmail.org/8.13.6.html
http://www.sendmail.com/company/advisory
ftp://ftp.sendmail.org/pub/sendmail/8.13.5.p0
ftp://ftp.sendmail.org/pub/sendmail/8.12.11.p0
http://xforce.iss.net/xforce/alerts/id/216

Credit

Thanks to Sendmail Inc. for reporting this vulnerability. Sendmail credits Internet Security Systems with providing information about this issue.

This document was written by Jeff Gennari.

Other Information

Date Public:2006-03-22
Date First Published:2006-03-22
Date Last Updated:2008-08-14
CERT Advisory: 
CVE-ID(s):CVE-2006-0058
NVD-ID(s):CVE-2006-0058
US-CERT Technical Alerts:TA06-081A
Metric:19.88
Document Revision:90

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2006 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader