CVE-2009-1490
published 2009-05-05CVE-2009-1490: Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code…
PriorityP335medium5CVSS 2.0
AVNACLAuNCNINAP
EXPLOIT
EPSS
12.61%
95.8th percentile
Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sendmail | < sendmail 8.13.2-0 (bookworm) | sendmail 8.13.2-0 (bookworm) |
| sendmail | sendmail | <= 8.13.1.2 | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qhrf-mg36-grcm: Heap-based buffer overflow in Sendmail before 8
ghsa_unreviewed·2022-05-02
CVE-2009-1490 [MEDIUM] CWE-119 GHSA-qhrf-mg36-grcm: Heap-based buffer overflow in Sendmail before 8
Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.
OSV
CVE-2009-1490: Heap-based buffer overflow in Sendmail before 8
osv·2009-05-05·CVSS 5.0
CVE-2009-1490 [MEDIUM] CVE-2009-1490: Heap-based buffer overflow in Sendmail before 8
Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.
Red Hat
sendmail: long first header can overflow into message body
vendor_redhat·2009-04-30·CVSS 5.0
CVE-2009-1490 [MEDIUM] sendmail: long first header can overflow into message body
sendmail: long first header can overflow into message body
Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.
Statement: Based on our analysis this issue does not have a security consequence and does not lead to a buffer overflow or denial of service. For more details of our technical evaluation see https://bugzilla.redhat.com/show_bug.cgi?id=499252#c18
Debian
CVE-2009-1490: sendmail - Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to ...
vendor_debian·2009·CVSS 5.0
CVE-2009-1490 [MEDIUM] CVE-2009-1490: sendmail - Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to ...
Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.
Scope: local
bookworm: resolved (fixed in 8.13.2-0)
bullseye: resolved (fixed in 8.13.2-0)
forky: resolved (fixed in 8.13.2-0)
sid: resolved (fixed in 8.13.2-0)
trixie: resolved (fixed in 8.13.2-0)
No detection rules found.
Bugzilla
CVE-2009-1490 sendmail: long first header can overflow into message body
bugzilla·2009-07-21·CVSS 5.0
CVE-2009-1490 [MEDIUM] CVE-2009-1490 sendmail: long first header can overflow into message body
CVE-2009-1490 sendmail: long first header can overflow into message body
This is a clone of bz #499252 to request a fix for this in 4.9.
Bugzilla
CVE-2009-1490 sendmail: long first header can overflow into message body
bugzilla·2009-05-05·CVSS 5.0
CVE-2009-1490 [MEDIUM] CVE-2009-1490 sendmail: long first header can overflow into message body
CVE-2009-1490 sendmail: long first header can overflow into message body
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-1490 to
the following vulnerability:
Name: CVE-2009-1490
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1490
Assigned: 20090430
Reference: MISC: http://www.nmrc.org/~thegnome/blog/apr09/
Reference: CONFIRM: http://www.sendmail.org/releases/8.13.2
Heap-based buffer overflow in Sendmail before 8.13.2 allows remote
attackers to cause a denial of service (daemon crash) and possibly
execute arbitrary code via a long X- header, as demonstrated by an
X-Testing header.
Discussion:
I'm confused by this one.
I tested it with Fedora 10 and also with Red Hat Enterprise Linux 4 (the latter is supposed to be "vulnerable" because it is version 8.
2009-05-05
Published