Vulnerability Note VU#834865
Sendmail signal I/O race condition
Overview
A race condition in Sendmail may allow a remote attacker to execute arbitrary code.
Description
Sendmail Sendmail is a widely used mail transfer agent (MTA). |
Impact
A remote, unauthenticated attacker could execute arbitrary code with the privileges of the Sendmail process. If Sendmail is running as root, the attacker could take complete control of an affected system. |
Solution
Upgrade This issue is corrected in Sendmail version 8.13.6. |
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Fedora Project | Affected | 08 Mar 2006 | 21 Mar 2006 |
| FreeBSD, Inc. | Affected | 08 Mar 2006 | 30 Mar 2006 |
| Gentoo Linux | Affected | 08 Mar 2006 | 22 Mar 2006 |
| Hewlett-Packard Company | Affected | 08 Mar 2006 | 27 Mar 2006 |
| IBM Corporation | Affected | 15 Mar 2006 | 22 Mar 2006 |
| NetBSD | Affected | 08 Mar 2006 | 03 Apr 2006 |
| OpenBSD | Affected | 21 Mar 2006 | 27 Mar 2006 |
| Red Hat, Inc. | Affected | 08 Mar 2006 | 21 Mar 2006 |
| Sendmail.org | Affected | 27 Feb 2006 | 21 Mar 2006 |
| Slackware Linux Inc. | Affected | 08 Mar 2006 | 24 Mar 2006 |
| Sun Microsystems, Inc. | Affected | 08 Mar 2006 | 27 Mar 2006 |
| SUSE Linux | Affected | 08 Mar 2006 | 21 Mar 2006 |
| Turbolinux | Affected | 08 Mar 2006 | 29 Mar 2006 |
| Ubuntu | Affected | 08 Mar 2006 | 22 Mar 2006 |
| Apple Computer, Inc. | Not Affected | 08 Mar 2006 | 22 Mar 2006 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- https://www.securecoding.cert.org/confluence/x/lwAV
- https://www.securecoding.cert.org/confluence/x/34At
- http://www.sendmail.org/8.13.6.html
- http://www.sendmail.com/company/advisory
- ftp://ftp.sendmail.org/pub/sendmail/8.13.5.p0
- ftp://ftp.sendmail.org/pub/sendmail/8.12.11.p0
- http://xforce.iss.net/xforce/alerts/id/216
Credit
Thanks to Sendmail Inc. for reporting this vulnerability. Sendmail credits Internet Security Systems with providing information about this issue.
This document was written by Jeff Gennari.
Other Information
- CVE IDs: CVE-2006-0058
- US-CERT Alert: TA06-081A
- Date Public: 22 Mar 2006
- Date First Published: 22 Mar 2006
- Date Last Updated: 22 Jul 2011
- Severity Metric: 19.88
- Document Revision: 91
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.