CVE-2006-7175
published 2007-03-27CVE-2006-7175: The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryption, which could…
PriorityP427high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
0.82%
54.5th percentile
The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryption, which could cause less secure channels to be used than desired.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sendmail | — | — |
| sendmail | sendmail | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2006-7175: sendmail - The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earl...
vendor_debian·2006·CVSS 7.5
CVE-2006-7175 [HIGH] CVE-2006-7175: sendmail - The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earl...
The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryption, which could cause less secure channels to be used than desired.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Red Hat
Sendmail allows SSLv2 during STARTTLS, and the CipherList config option isn't supported so you can't turn it off
vendor_redhat·CVSS 7.5
CVE-2006-7175 [HIGH] Sendmail allows SSLv2 during STARTTLS, and the CipherList config option isn't supported so you can't turn it off
Sendmail allows SSLv2 during STARTTLS, and the CipherList config option isn't supported so you can't turn it off
The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryption, which could cause less secure channels to be used than desired.
Statement: ** DISPUTED ** Sendmail classes the CipherList directive as "for future release"; currently unsupported and undocumented. Therefore the lack of support for the CipherList directive in various Red Hat products is not a vulnerability.
GHSA
GHSA-26xp-84m3-w6wh: The version of Sendmail 8
ghsa_unreviewed·2022-05-01
CVE-2006-7175 [HIGH] GHSA-26xp-84m3-w6wh: The version of Sendmail 8
The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryption, which could cause less secure channels to be used than desired.
No detection rules found.
No public exploits indexed.
2007-03-27
Published