CVE-2006-1173

CWE-3999 documents8 sources
Severity
5.0MEDIUM
EPSS
21.5%
top 4.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 7
Latest updateMay 3

Description

Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debiansendmail< 8.13.7-1+3
NVDsendmail/sendmail8.13.6+36

Patches

🔴Vulnerability Details

3
GHSA
GHSA-2rh9-mcg8-96mq: Sendmail before 82022-05-03
CVEList
CVE-2006-1173: Sendmail before 82006-06-07
OSV
CVE-2006-1173: Sendmail before 82006-06-07

📋Vendor Advisories

3
Red Hat
security flaw2006-06-14
BSD
FreeBSD-SA-06:17.sendmail: Incorrect multipart message handling in Sendmail2006-06-14
Debian
CVE-2006-1173: sendmail - Sendmail before 8.13.7 allows remote attackers to cause a denial of service via ...2006

💬Community

2
Bugzilla
CVE-2006-1173 security flaw2018-08-16
Bugzilla
CVE-2006-1173 Sendmail - Deeply nested malformed MIME denial of service attack2006-06-15