cbcvebase.
CVE-2006-4434
published 2006-08-29

CVE-2006-4434: Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a…

PriorityP271high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
4.33%
90.1th percentile
Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected."

Affected

8 ranges
VendorProductVersion rangeFixed in
debiansendmail< sendmail 8.13.8-1 (bookworm)sendmail 8.13.8-1 (bookworm)
sendmailsendmail< 8.13.88.13.8
sendmailsendmail
sendmailsendmail
sendmailsendmail>= 0 < 8.13.8-18.13.8-1
sendmailsendmail>= 0 < 8.13.8-18.13.8-1
sendmailsendmail>= 0 < 8.13.8-18.13.8-1
sendmailsendmail>= 0 < 8.13.8-18.13.8-1

Detection & IOCsextracted from sources · hover to see the quote

  • ·The original Sendmail developer disputed the practical severity of this use-after-free, noting the process terminates via exit(3) regardless and no mail delivery or reception is affected; the only observable impact is potential core dump files on disk.
  • ·It is unclear whether CVE-2006-4434 overlaps with CVE-2006-1173 or CVE-2007-2246; detections targeting one may or may not cover the others.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vulncheck7.5HIGH
vendor_debian7.5MEDIUM
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.