CVE-2006-0058
published 2006-03-22CVE-2006-0058: Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes…
PriorityP356high7.6CVSS 2.0
AVNACHAuNCCICAC
EXPLOIT
EPSS
28.14%
97.9th percentile
Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sendmail | < sendmail 8.13.6-1 (bookworm) | sendmail 8.13.6-1 (bookworm) |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | >= 0 < 8.13.6-1 | 8.13.6-1 |
| sendmail | sendmail | >= 0 < 8.13.6-1 | 8.13.6-1 |
| sendmail | sendmail | >= 0 < 8.13.6-1 | 8.13.6-1 |
| sendmail | sendmail | >= 0 < 8.13.6-1 | 8.13.6-1 |
Detection & IOCsextracted from sources · hover to see the quote
- →The exploit targets Sendmail 8.13.x before 8.13.6 on TCP port 25. Detection should look for SMTP sessions that send an unusually large DATA payload (~32764 bytes of 0x7f bytes) followed by repeated probe sequences to trigger a signal handler race condition. ↗
- →The exploit sends a payload buffer filled with 0x7f bytes (32764 bytes) as the message body to trigger the timeout race. Network signatures should look for SMTP DATA bodies consisting predominantly of 0x7f bytes at this size. ↗
- →The attack exploits the race between setjmp/longjmp and asynchronous signal handling in Sendmail. The attacker forces an I/O timeout at a precise moment during SMTP DATA phase. Monitor for SMTP 451 timeout responses immediately following a large DATA submission as a potential exploitation indicator. ↗
- →The vulnerability also involves a buffer in sm_syslog() that could be used as an attack vector. Monitor sendmail log entries for anomalous or oversized syslog messages that may indicate exploitation attempts. ↗
- ·On Red Hat Enterprise Linux 2.1, Sendmail is configured by default to only accept connections from localhost, limiting remote exploitability to instances where Sendmail has been reconfigured to listen on external interfaces. ↗
- ·There is no known workaround for this vulnerability other than completely disabling sendmail. ↗
- ·The CERT-supplied patch may generate compiler warnings about offsets, which CERT and Sendmail consider harmless. Additionally, on systems where time_t != int (e.g., s390x), the original patch caused a regression and required modification. ↗
CVSS provenance
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
osv7.6HIGH
vendor_debian7.6HIGH
vendor_redhat7.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rwqm-33xf-cwgq: Signal handler race condition in Sendmail 8
ghsa_unreviewed·2022-05-03
CVE-2006-0058 [HIGH] GHSA-rwqm-33xf-cwgq: Signal handler race condition in Sendmail 8
Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.
OSV
CVE-2006-0058: Signal handler race condition in Sendmail 8
osv·2006-03-22·CVSS 7.6
CVE-2006-0058 [HIGH] CVE-2006-0058: Signal handler race condition in Sendmail 8
Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.
Red Hat
security flaw
vendor_redhat·2006-03-22·CVSS 7.6
CVE-2006-0058 [HIGH] security flaw
security flaw
Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.
BSD
FreeBSD-SA-06:13.sendmail: Race condition in sendmail
bsd_advisories·2006-03-22·CVSS 7.6
CVE-2006-0058 [HIGH] FreeBSD-SA-06:13.sendmail: Race condition in sendmail
FreeBSD-SA-06:13.sendmail Security Advisory
The FreeBSD Project
Topic: Race condition in sendmail
Category: contrib
Module: contrib_sendmail
Announced: 2006-03-22
Affects: All FreeBSD releases.
Corrected: 2006-03-22 16:01:08 UTC (RELENG_6, 6.1-STABLE)
2006-03-22 16:01:38 UTC (RELENG_6_0, 6.0-RELEASE-p6)
2006-03-22 16:01:56 UTC (RELENG_5, 5.5-STABLE)
2006-03-22 16:02:17 UTC (RELENG_5_4, 5.4-RELEASE-p13)
2006-03-22 16:02:35 UTC (RELENG_5_3, 5.3-RELEASE-p28)
2006-03-22 16:02:49 UTC (RELENG_4, 4.11-STABLE)
2006-03-22 16:03:05 UTC (RELENG_4_11, 4.11-RELEASE-p16)
2006-03-22 16:03:25 UTC (RELENG_4_10, 4.10-RELEASE-p22)
CVE Name: CVE-2006-0058
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections,
Debian
CVE-2006-0058: sendmail - Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote att...
vendor_debian·2006·CVSS 7.6
CVE-2006-0058 [HIGH] CVE-2006-0058: sendmail - Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote att...
Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.
Scope: local
bookworm: resolved (fixed in 8.13.6-1)
bullseye: resolved (fixed in 8.13.6-1)
forky: resolved (fixed in 8.13.6-1)
sid: resolved (fixed in 8.13.6-1)
trixie: resolved (fixed in 8.13.6-1)
No detection rules found.
Bugzilla
CVE-2006-0058 security flaw
bugzilla·2018-08-16·CVSS 7.6
CVE-2006-0058 [HIGH] CVE-2006-0058 security flaw
CVE-2006-0058 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.
Bugzilla
CVE-2006-0058 Sendmail race condition issue
bugzilla·2006-03-22·CVSS 7.6
CVE-2006-0058 [HIGH] CVE-2006-0058 Sendmail race condition issue
CVE-2006-0058 Sendmail race condition issue
Sendmail race condition issue
CERT has reported a race condition issue in sendmail which may lead to
arbitrary remote code execution.
CERT has assinged this issue the name VU#834865
this is the FL version of bug 184465
Discussion:
From CERT VU#834865[1]:
The Problem
Sendmail contains a race condition caused by the improper handling of
asynchronous signals. In particular, by forcing SMTP server to have an I/O
timeout at exactly the correct instant, the attacker may be able to execute
arbitrary code with the privileges of the Sendmail process.
More information is available in the Sendmail version 8.13.6 release page[2]
and the Sendmail MTA Security Vulnerability Advisory[3].
Versions of Sendmail prior to 8.13.6 are affected.
II. Impact
A
Bugzilla
CVE-2006-0058 Sendmail race condition issue
bugzilla·2006-03-08·CVSS 7.6
CVE-2006-0058 [HIGH] CVE-2006-0058 Sendmail race condition issue
CVE-2006-0058 Sendmail race condition issue
Sendmail race condition issue
CERT has reported a race condition issue in sendmail which may lead to
arbitrary remote code execution.
CERT has assinged this issue the name VU#834865
This issue also affects RHEL3
This issue also affects RHEL2.1
Discussion:
Created attachment 125842
Proposed patch from CERT
To quote CERT regarding this patch:
A patch to correct this issue in sendmail versions 8.13 is provided
below. The patch also eliminates potential integer overflows in how
sendmail handles message headers. This patch was prepared manually by
Sendmail and in our experience will generate warnings about
offsets. We've discussed this with Sendmail and believe it to be
harmless. Aside from that, CERT/CC has not verified this patch, what
issu
Bugzilla
CVE-2006-0058 Sendmail race condition issue
bugzilla·2006-03-08·CVSS 7.6
CVE-2006-0058 [HIGH] CVE-2006-0058 Sendmail race condition issue
CVE-2006-0058 Sendmail race condition issue
Sendmail race condition issue
CERT has reported a race condition issue in sendmail which may lead to
arbitrary remote code execution.
CERT has assinged this issue the name VU#834865
Discussion:
attachment 125842 is the proposed patch from CERT
To quote CERT regarding this patch:
A patch to correct this issue in sendmail versions 8.13 is provided
below. The patch also eliminates potential integer overflows in how
sendmail handles message headers. This patch was prepared manually by
Sendmail and in our experience will generate warnings about
offsets. We've discussed this with Sendmail and believe it to be
harmless. Aside from that, CERT/CC has not verified this patch, what
issues are corrected, and how those issues are corrected.
---
This
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:13.sendmail.ascftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-010.txt.ascftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.24/SCOSA-2006.24.txtftp://patches.sgi.com/support/free/security/advisories/20060302-01-Pftp://patches.sgi.com/support/free/security/advisories/20060401-01-Uhttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00629555http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635http://secunia.com/advisories/19342http://secunia.com/advisories/19345http://secunia.com/advisories/19346http://secunia.com/advisories/19349http://secunia.com/advisories/19356http://secunia.com/advisories/19360http://secunia.com/advisories/19361http://secunia.com/advisories/19363http://secunia.com/advisories/19367http://secunia.com/advisories/19368http://secunia.com/advisories/19394http://secunia.com/advisories/19404http://secunia.com/advisories/19407http://secunia.com/advisories/19450http://secunia.com/advisories/19466http://secunia.com/advisories/19532http://secunia.com/advisories/19533http://secunia.com/advisories/19676http://secunia.com/advisories/19774http://secunia.com/advisories/20243http://secunia.com/advisories/20723http://securityreason.com/securityalert/612http://securityreason.com/securityalert/743http://securitytracker.com/id?1015801http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.619600http://sunsolve.sun.com/search/document.do?assetkey=1-26-102262-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-102324-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-200494-1http://support.avaya.com/elmodocs2/security/ASA-2006-074.htmhttp://support.avaya.com/elmodocs2/security/ASA-2006-078.htmhttp://www-1.ibm.com/support/search.wss?rs=0&q=IY82992&apar=onlyhttp://www-1.ibm.com/support/search.wss?rs=0&q=IY82993&apar=onlyhttp://www-1.ibm.com/support/search.wss?rs=0&q=IY82994&apar=onlyhttp://www.ciac.org/ciac/bulletins/q-151.shtmlhttp://www.debian.org/security/2006/dsa-1015http://www.f-secure.com/security/fsc-2006-2.shtmlhttp://www.gentoo.org/security/en/glsa/glsa-200603-21.xmlhttp://www.iss.net/threats/216.htmlhttp://www.kb.cert.org/vuls/id/834865http://www.mandriva.com/security/advisories?name=MDKSA-2006:058http://www.novell.com/linux/security/advisories/2006_17_sendmail.htmlhttp://www.openbsd.org/errata38.html#sendmailhttp://www.openpkg.org/security/advisories/OpenPKG-SA-2006.007-sendmail.htmlhttp://www.osvdb.org/24037http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00017.htmlhttp://www.redhat.com/archives/fedora-announce-list/2006-April/msg00018.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0264.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0265.htmlhttp://www.securityfocus.com/archive/1/428536/100/0/threadedhttp://www.securityfocus.com/archive/1/428656/100/0/threadedhttp://www.securityfocus.com/bid/17192http://www.sendmail.com/company/advisory/index.shtmlhttp://www.us-cert.gov/cas/techalerts/TA06-081A.htmlhttp://www.vupen.com/english/advisories/2006/1049http://www.vupen.com/english/advisories/2006/1051http://www.vupen.com/english/advisories/2006/1068http://www.vupen.com/english/advisories/2006/1072http://www.vupen.com/english/advisories/2006/1139http://www.vupen.com/english/advisories/2006/1157http://www.vupen.com/english/advisories/2006/1529http://www.vupen.com/english/advisories/2006/2189http://www.vupen.com/english/advisories/2006/2490http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=2751https://exchange.xforce.ibmcloud.com/vulnerabilities/24584https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11074https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1689ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:13.sendmail.ascftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-010.txt.ascftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.24/SCOSA-2006.24.txtftp://patches.sgi.com/support/free/security/advisories/20060302-01-Pftp://patches.sgi.com/support/free/security/advisories/20060401-01-Uhttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00629555http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635http://secunia.com/advisories/19342http://secunia.com/advisories/19345http://secunia.com/advisories/19346http://secunia.com/advisories/19349http://secunia.com/advisories/19356http://secunia.com/advisories/19360http://secunia.com/advisories/19361http://secunia.com/advisories/19363http://secunia.com/advisories/19367http://secunia.com/advisories/19368http://secunia.com/advisories/19394http://secunia.com/advisories/19404http://secunia.com/advisories/19407http://secunia.com/advisories/19450http://secunia.com/advisories/19466http://secunia.com/advisories/19532http://secunia.com/advisories/19533http://secunia.com/advisories/19676http://secunia.com/advisories/19774
+ 48 more references
2006-03-22
Published