5
CVSSv2

CVE-2009-1490

Published: 05/05/2009 Updated: 17/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Heap-based buffer overflow in Sendmail prior to 8.13.2 allows remote malicious users to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.

Vulnerable Product Search on Vulmon Subscribe to Product

sendmail sendmail 5

sendmail sendmail 5.65

sendmail sendmail 2.6.1

sendmail sendmail 8.12

sendmail sendmail 8.11.7

sendmail sendmail 8.11.0

sendmail sendmail 8.10.2

sendmail sendmail 2.6

sendmail sendmail 8.12.7

sendmail sendmail 8.12.8

sendmail sendmail 8.12.1

sendmail sendmail 8.12.10

sendmail sendmail 8.9.1

sendmail sendmail 8.9.0

sendmail sendmail 8.10.0

sendmail sendmail 5.61

sendmail sendmail 3.0

sendmail sendmail 3.0.1

sendmail sendmail 8.11.1

sendmail sendmail 8.11.2

sendmail sendmail 8.7.8

sendmail sendmail 8.7.7

sendmail sendmail 8.12.5

sendmail sendmail 8.12.6

sendmail sendmail 8.8.8

sendmail sendmail 8.6.7

sendmail sendmail 4.55

sendmail sendmail 8.10

sendmail sendmail 3.0.2

sendmail sendmail 3.0.3

sendmail sendmail 8.11.4

sendmail sendmail 8.11.3

sendmail sendmail 8.7.6

sendmail sendmail 8.7.10

sendmail sendmail 8.12.3

sendmail sendmail 8.12.4

sendmail sendmail 8.9.3

sendmail sendmail 8.9.2

sendmail sendmail 5.59

sendmail sendmail 4.1

sendmail sendmail 2.6.2

sendmail sendmail 8.11.6

sendmail sendmail 8.12.0

sendmail sendmail 8.10.1

sendmail sendmail 8.11.5

sendmail sendmail 8.7.9

sendmail sendmail 8.12.9

sendmail sendmail 8.13.0

sendmail sendmail 8.12.11

sendmail sendmail 8.12.2

sendmail sendmail

Exploits

source: wwwsecurityfocuscom/bid/34944/info Sendmail is prone to a heap-based buffer-overflow vulnerability because it fails to adequately bounds-check user-supplied input before copying it to an insufficiently sized buffer Successfully exploiting this issue may allow an attacker to execute arbitrary code with the privileges of the user ...