CVE-2006-4434
published 2006-08-29CVE-2006-4434: Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a…
PriorityP271high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
4.33%
90.1th percentile
Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected."
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sendmail | < sendmail 8.13.8-1 (bookworm) | sendmail 8.13.8-1 (bookworm) |
| sendmail | sendmail | < 8.13.8 | 8.13.8 |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | >= 0 < 8.13.8-1 | 8.13.8-1 |
| sendmail | sendmail | >= 0 < 8.13.8-1 | 8.13.8-1 |
| sendmail | sendmail | >= 0 < 8.13.8-1 | 8.13.8-1 |
| sendmail | sendmail | >= 0 < 8.13.8-1 | 8.13.8-1 |
Detection & IOCsextracted from sources · hover to see the quote
- ·The original Sendmail developer disputed the practical severity of this use-after-free, noting the process terminates via exit(3) regardless and no mail delivery or reception is affected; the only observable impact is potential core dump files on disk. ↗
- ·It is unclear whether CVE-2006-4434 overlaps with CVE-2006-1173 or CVE-2007-2246; detections targeting one may or may not cover the others. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vulncheck7.5HIGH
vendor_debian7.5MEDIUM
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-535c-fwmj-7hhw: Use-after-free vulnerability in Sendmail before 8
ghsa_unreviewed·2022-05-01
CVE-2006-4434 [MEDIUM] CWE-416 GHSA-535c-fwmj-7hhw: Use-after-free vulnerability in Sendmail before 8
Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected."
GHSA
GHSA-35h8-v5vr-r4m7: Unspecified vulnerability in HP-UX B
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2007-2246 [MEDIUM] GHSA-35h8-v5vr-r4m7: Unspecified vulnerability in HP-UX B
Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.1; allows remote attackers to cause a denial of service via unknown attack vectors. NOTE: due to the lack of details from HP, it is not known whether this issue is a duplicate of another CVE such as CVE-2006-1173 or CVE-2006-4434.
OSV
CVE-2006-4434: Use-after-free vulnerability in Sendmail before 8
osv·2006-08-29·CVSS 7.5
CVE-2006-4434 [HIGH] CVE-2006-4434: Use-after-free vulnerability in Sendmail before 8
Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected."
VulnCheck
sendmail sendmail Use After Free
vulncheck·2006·CVSS 7.5
CVE-2006-4434 [HIGH] sendmail sendmail Use After Free
sendmail sendmail Use After Free
Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected."
Affected: sendmail sendmail
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigat
Debian
CVE-2006-4434: sendmail - Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers t...
vendor_debian·2006·CVSS 7.5
CVE-2006-4434 [HIGH] CVE-2006-4434: sendmail - Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers t...
Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected."
Scope: local
bookworm: resolved (fixed in 8.13.8-1)
bullseye: resolved (fixed in 8.13.8-1)
forky: resolved (fixed in 8.13.8-1)
sid: resolved (fixed in 8.13.8-1)
trixie: resolved (fixed in 8.13.8-1)
Red Hat
CVE-2006-4434: Use-after-free vulnerability in Sendmail before 8
vendor_redhat·CVSS 7.5
CVE-2006-4434 [HIGH] CVE-2006-4434: Use-after-free vulnerability in Sendmail before 8
Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected."
Statement: This flaw causes a crash but does not result in a denial of service against Sendmail and is therefore not a security issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/21637http://secunia.com/advisories/21641http://secunia.com/advisories/21696http://secunia.com/advisories/21700http://secunia.com/advisories/21749http://secunia.com/advisories/22369http://securitytracker.com/id?1016753http://sunsolve.sun.com/search/document.do?assetkey=1-26-102664-1http://www.attrition.org/pipermail/vim/2006-August/000999.htmlhttp://www.debian.org/security/2006/dsa-1164http://www.mandriva.com/security/advisories?name=MDKSA-2006:156http://www.novell.com/linux/security/advisories/2006_21_sr.htmlhttp://www.openbsd.org/errata.html#sendmail3http://www.openbsd.org/errata38.html#sendmail3http://www.osvdb.org/28193http://www.securityfocus.com/bid/19714http://www.sendmail.org/releases/8.13.8.htmlhttp://www.vupen.com/english/advisories/2006/3393http://www.vupen.com/english/advisories/2006/3994http://secunia.com/advisories/21637http://secunia.com/advisories/21641http://secunia.com/advisories/21696http://secunia.com/advisories/21700http://secunia.com/advisories/21749http://secunia.com/advisories/22369http://securitytracker.com/id?1016753http://sunsolve.sun.com/search/document.do?assetkey=1-26-102664-1http://www.attrition.org/pipermail/vim/2006-August/000999.htmlhttp://www.debian.org/security/2006/dsa-1164http://www.mandriva.com/security/advisories?name=MDKSA-2006:156http://www.novell.com/linux/security/advisories/2006_21_sr.htmlhttp://www.openbsd.org/errata.html#sendmail3http://www.openbsd.org/errata38.html#sendmail3http://www.osvdb.org/28193http://www.securityfocus.com/bid/19714http://www.sendmail.org/releases/8.13.8.htmlhttp://www.vupen.com/english/advisories/2006/3393http://www.vupen.com/english/advisories/2006/3994
2006-08-29
Published
Exploited in the wild