Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-4434

Опубликовано: 29 авг. 2006
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected."

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sendmail:sendmail:*:*:*:*:*:*:*:*
Версия до 8.13.8 (исключая)

EPSS

Процентиль: 91%
0.07587
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 19 лет назад

Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected."

CVSS3: 7.5
debian
около 19 лет назад

Use-after-free vulnerability in Sendmail before 8.13.8 allows remote a ...

CVSS3: 7.5
github
больше 3 лет назад

Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected."

EPSS

Процентиль: 91%
0.07587
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-416