Lucene search

K
freebsdFreeBSD08AC7B8B-BB30-11DA-B2FB-000E0C2E438A
HistoryMar 22, 2006 - 12:00 a.m.

sendmail -- race condition vulnerability

2006-03-2200:00:00
vuxml.freebsd.org
39

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

EPSS

0.94

Percentile

99.2%

Problem Description
A race condition has been reported to exist in the handling
by sendmail of asynchronous signals.
Impact
A remote attacker may be able to execute arbitrary code with
the privileges of the user running sendmail, typically
root.
Workaround
There is no known workaround other than disabling
sendmail.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchsendmail< 8.13.6UNKNOWN
FreeBSDanynoarchfreebsd= 6.0UNKNOWN
FreeBSDanynoarchfreebsd< 6.0_6UNKNOWN

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

EPSS

0.94

Percentile

99.2%