CVE-2006-1173
published 2006-06-07CVE-2006-1173: Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
5.17%
91.5th percentile
Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files.
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sendmail | < sendmail 8.13.7-1 (bookworm) | sendmail 8.13.7-1 (bookworm) |
| eset | nod32_antivirus | — | — |
| incredimail | incredimail | — | — |
| kaspersky_lab | kaspersky_internet_security_suite | — | — |
| microsoft | outlook_express | — | — |
| mozilla | thunderbird | — | — |
| opera | opera | — | — |
| sendmail | sendmail | <= 8.13.6 | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gg7f-9m2h-jpjx: Norton Antivirus in Norton Internet Security 15
ghsa_unreviewed·2022-05-14·CVSS 5.0
CVE-2008-5427 [MEDIUM] GHSA-gg7f-9m2h-jpjx: Norton Antivirus in Norton Internet Security 15
Norton Antivirus in Norton Internet Security 15.5.0.23 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service (stack consumption or other resource consumption) via a large e-mail message, a related issue to CVE-2006-1173.
GHSA
GHSA-phxj-wq6j-j348: The MimeOleClearDirtyTree function in InetComm
ghsa_unreviewed·2022-05-14·CVSS 5.0
CVE-2008-5424 [MEDIUM] GHSA-phxj-wq6j-j348: The MimeOleClearDirtyTree function in InetComm
The MimeOleClearDirtyTree function in InetComm.dll in Microsoft Outlook Express 6.00.2900.5512 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service (infinite loop) via a large e-mail message, a related issue to CVE-2006-1173.
GHSA
GHSA-34wr-q9h7-hx52: ESet NOD32 2
ghsa_unreviewed·2022-05-14·CVSS 5.0
CVE-2008-5425 [MEDIUM] GHSA-34wr-q9h7-hx52: ESet NOD32 2
ESet NOD32 2.70.0039.0000 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service (stack consumption or other resource consumption) via a large e-mail message, a related issue to CVE-2006-1173.
GHSA
GHSA-j6h9-29jj-pxjv: Kaspersky Internet Security Suite 2009 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messa
ghsa_unreviewed·2022-05-14·CVSS 5.0
CVE-2008-5426 [MEDIUM] GHSA-j6h9-29jj-pxjv: Kaspersky Internet Security Suite 2009 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messa
Kaspersky Internet Security Suite 2009 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service (stack consumption or other resource consumption) via a large e-mail message, a related issue to CVE-2006-1173.
GHSA
GHSA-mmj8-qxh6-33c9: Incredimail build 5853710 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many
ghsa_unreviewed·2022-05-14·CVSS 5.0
CVE-2008-5429 [MEDIUM] GHSA-mmj8-qxh6-33c9: Incredimail build 5853710 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many
Incredimail build 5853710 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service (stack consumption or other resource consumption) via a large e-mail message, a related issue to CVE-2006-1173.
GHSA
GHSA-wrqj-hmv6-rx3j: Opera 9
ghsa_unreviewed·2022-05-14·CVSS 5.0
CVE-2008-5428 [MEDIUM] GHSA-wrqj-hmv6-rx3j: Opera 9
Opera 9.51 on Windows XP does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service (stack consumption or other resource consumption) via a large e-mail message, a related issue to CVE-2006-1173.
GHSA
GHSA-5j5r-p4gq-qg52: Mozilla Thunderbird 2
ghsa_unreviewed·2022-05-14·CVSS 5.0
CVE-2008-5430 [MEDIUM] GHSA-5j5r-p4gq-qg52: Mozilla Thunderbird 2
Mozilla Thunderbird 2.0.14 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which might allow remote attackers to cause a denial of service (stack consumption or other resource consumption) via a large e-mail message, a related issue to CVE-2006-1173.
GHSA
GHSA-2rh9-mcg8-96mq: Sendmail before 8
ghsa_unreviewed·2022-05-03
CVE-2006-1173 [MEDIUM] GHSA-2rh9-mcg8-96mq: Sendmail before 8
Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files.
GHSA
GHSA-35h8-v5vr-r4m7: Unspecified vulnerability in HP-UX B
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2007-2246 [MEDIUM] GHSA-35h8-v5vr-r4m7: Unspecified vulnerability in HP-UX B
Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.1; allows remote attackers to cause a denial of service via unknown attack vectors. NOTE: due to the lack of details from HP, it is not known whether this issue is a duplicate of another CVE such as CVE-2006-1173 or CVE-2006-4434.
OSV
CVE-2006-1173: Sendmail before 8
osv·2006-06-07·CVSS 5.0
CVE-2006-1173 [MEDIUM] CVE-2006-1173: Sendmail before 8
Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files.
Red Hat
security flaw
vendor_redhat·2006-06-14·CVSS 5.0
CVE-2006-1173 [MEDIUM] security flaw
security flaw
Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files.
BSD
FreeBSD-SA-06:17.sendmail: Incorrect multipart message handling in Sendmail
bsd_advisories·2006-06-14·CVSS 5.0
CVE-2006-1173 [MEDIUM] FreeBSD-SA-06:17.sendmail: Incorrect multipart message handling in Sendmail
FreeBSD-SA-06:17.sendmail Security Advisory
The FreeBSD Project
Topic: Incorrect multipart message handling in Sendmail
Category: contrib
Module: contrib_sendmail
Announced: 2006-06-14
Affects: All FreeBSD releases.
Corrected: 2006-06-14 15:58:23 UTC (RELENG_6, 6.1-STABLE)
2006-06-14 15:59:28 UTC (RELENG_6_1, 6.1-RELEASE-p2)
2006-06-14 15:59:37 UTC (RELENG_6_0, 6.0-RELEASE-p9)
2006-06-14 16:00:02 UTC (RELENG_5, 5.5-STABLE)
2006-06-14 16:00:22 UTC (RELENG_5_5, 5.5-RELEASE-p2)
2006-06-14 16:00:42 UTC (RELENG_5_4, 5.4-RELEASE-p16)
2006-06-14 16:00:56 UTC (RELENG_5_3, 5.3-RELEASE-p31)
2006-06-14 16:01:06 UTC (RELENG_4, 4.11-STABLE)
2006-06-14 16:01:21 UTC (RELENG_4_11, 4.11-RELEASE-p19)
CVE Name: CVE-2006-1173
For general information regarding FreeBSD Security Advisories,
including descript
Debian
CVE-2006-1173: sendmail - Sendmail before 8.13.7 allows remote attackers to cause a denial of service via ...
vendor_debian·2006·CVSS 5.0
CVE-2006-1173 [MEDIUM] CVE-2006-1173: sendmail - Sendmail before 8.13.7 allows remote attackers to cause a denial of service via ...
Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files.
Scope: local
bookworm: resolved (fixed in 8.13.7-1)
bullseye: resolved (fixed in 8.13.7-1)
forky: resolved (fixed in 8.13.7-1)
sid: resolved (fixed in 8.13.7-1)
trixie: resolved (fixed in 8.13.7-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-1173 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2006-1173 [MEDIUM] CVE-2006-1173 security flaw
CVE-2006-1173 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files.
Bugzilla
CVE-2006-1173 Sendmail - Deeply nested malformed MIME denial of service attack
bugzilla·2006-06-15·CVSS 5.0
CVE-2006-1173 [MEDIUM] CVE-2006-1173 Sendmail - Deeply nested malformed MIME denial of service attack
CVE-2006-1173 Sendmail - Deeply nested malformed MIME denial of service attack
Description of problem:
Sendmail does not properly handle malformed multipart MIME messages. This
vulnerability may allow a remote, unauthenticated attacker to cause a
denial-of-service condition.
Version-Release number of selected component (if applicable):
Apparently all Legacy releases.
Additional info:
Red Hat issued RHSA-2006-0515 today for CVE-2006-1173 for RHEL 2.1,
RHEL 3, and RHEL 4. This issue was rated as having an important impact
by the Red Hat Security Response Team.
http://rhn.redhat.com/errata/RHSA-2006-0515.html
"A flaw in the handling of multi-part MIME messages was discovered in
Sendmail. A remote attacker could create a carefully crafted message that
could crash the sendmail process dur
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:17.sendmail.ascftp://patches.sgi.com/support/free/security/advisories/20060601-01-Pftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.aschttp://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635http://lists.suse.com/archive/suse-security-announce/2006-Jun/0006.htmlhttp://secunia.com/advisories/15779http://secunia.com/advisories/20473http://secunia.com/advisories/20641http://secunia.com/advisories/20650http://secunia.com/advisories/20651http://secunia.com/advisories/20654http://secunia.com/advisories/20673http://secunia.com/advisories/20675http://secunia.com/advisories/20679http://secunia.com/advisories/20683http://secunia.com/advisories/20684http://secunia.com/advisories/20694http://secunia.com/advisories/20726http://secunia.com/advisories/20782http://secunia.com/advisories/21042http://secunia.com/advisories/21160http://secunia.com/advisories/21327http://secunia.com/advisories/21612http://secunia.com/advisories/21647http://securitytracker.com/id?1016295http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.631382http://sunsolve.sun.com/search/document.do?assetkey=1-26-102460-1http://support.avaya.com/elmodocs2/security/ASA-2006-148.htmhttp://www-1.ibm.com/support/search.wss?rs=0&q=IY85415&apar=onlyhttp://www-1.ibm.com/support/search.wss?rs=0&q=IY85930&apar=onlyhttp://www.debian.org/security/2006/dsa-1155http://www.f-secure.com/security/fsc-2006-5.shtmlhttp://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-18.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200606-19.xmlhttp://www.kb.cert.org/vuls/id/146718http://www.mandriva.com/security/advisories?name=MDKSA-2006:104http://www.openbsd.org/errata38.html#sendmail2http://www.osvdb.org/26197http://www.redhat.com/support/errata/RHSA-2006-0515.htmlhttp://www.securityfocus.com/archive/1/437928/100/0/threadedhttp://www.securityfocus.com/archive/1/438241/100/0/threadedhttp://www.securityfocus.com/archive/1/438330/100/0/threadedhttp://www.securityfocus.com/archive/1/440744/100/0/threadedhttp://www.securityfocus.com/archive/1/442939/100/0/threadedhttp://www.securityfocus.com/bid/18433http://www.sendmail.com/security/advisories/SA-200605-01.txt.aschttp://www.vupen.com/english/advisories/2006/2189http://www.vupen.com/english/advisories/2006/2351http://www.vupen.com/english/advisories/2006/2388http://www.vupen.com/english/advisories/2006/2389http://www.vupen.com/english/advisories/2006/2390http://www.vupen.com/english/advisories/2006/2798http://www.vupen.com/english/advisories/2006/3135https://exchange.xforce.ibmcloud.com/vulnerabilities/27128https://issues.rpath.com/browse/RPL-526https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11253ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:17.sendmail.ascftp://patches.sgi.com/support/free/security/advisories/20060601-01-Pftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.aschttp://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635http://lists.suse.com/archive/suse-security-announce/2006-Jun/0006.htmlhttp://secunia.com/advisories/15779http://secunia.com/advisories/20473http://secunia.com/advisories/20641http://secunia.com/advisories/20650http://secunia.com/advisories/20651http://secunia.com/advisories/20654http://secunia.com/advisories/20673http://secunia.com/advisories/20675http://secunia.com/advisories/20679http://secunia.com/advisories/20683http://secunia.com/advisories/20684http://secunia.com/advisories/20694http://secunia.com/advisories/20726http://secunia.com/advisories/20782http://secunia.com/advisories/21042http://secunia.com/advisories/21160http://secunia.com/advisories/21327http://secunia.com/advisories/21612http://secunia.com/advisories/21647http://securitytracker.com/id?1016295http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.631382http://sunsolve.sun.com/search/document.do?assetkey=1-26-102460-1http://support.avaya.com/elmodocs2/security/ASA-2006-148.htmhttp://www-1.ibm.com/support/search.wss?rs=0&q=IY85415&apar=onlyhttp://www-1.ibm.com/support/search.wss?rs=0&q=IY85930&apar=onlyhttp://www.debian.org/security/2006/dsa-1155http://www.f-secure.com/security/fsc-2006-5.shtmlhttp://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-18.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200606-19.xmlhttp://www.kb.cert.org/vuls/id/146718http://www.mandriva.com/security/advisories?name=MDKSA-2006:104http://www.openbsd.org/errata38.html#sendmail2http://www.osvdb.org/26197http://www.redhat.com/support/errata/RHSA-2006-0515.htmlhttp://www.securityfocus.com/archive/1/437928/100/0/threadedhttp://www.securityfocus.com/archive/1/438241/100/0/threadedhttp://www.securityfocus.com/archive/1/438330/100/0/threadedhttp://www.securityfocus.com/archive/1/440744/100/0/threadedhttp://www.securityfocus.com/archive/1/442939/100/0/threaded
+ 12 more references
2006-06-07
Published