Lucene search

K
nvd[email protected]NVD:CVE-2009-1490
HistoryMay 05, 2009 - 7:30 p.m.

CVE-2009-1490

2009-05-0519:30:00
CWE-119
web.nvd.nist.gov

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

8

Confidence

High

EPSS

0.065

Percentile

93.7%

Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.

Affected configurations

NVD
Node
sendmailsendmailRange≀8.13.1.2
OR
sendmailsendmailMatch2.6
OR
sendmailsendmailMatch2.6nt
OR
sendmailsendmailMatch2.6.1
OR
sendmailsendmailMatch2.6.1nt
OR
sendmailsendmailMatch2.6.2
OR
sendmailsendmailMatch3.0
OR
sendmailsendmailMatch3.0nt
OR
sendmailsendmailMatch3.0.1
OR
sendmailsendmailMatch3.0.1nt
OR
sendmailsendmailMatch3.0.2
OR
sendmailsendmailMatch3.0.2nt
OR
sendmailsendmailMatch3.0.3
OR
sendmailsendmailMatch4.1
OR
sendmailsendmailMatch4.55
OR
sendmailsendmailMatch5
OR
sendmailsendmailMatch5.59
OR
sendmailsendmailMatch5.61
OR
sendmailsendmailMatch5.65
OR
sendmailsendmailMatch8.6.7
OR
sendmailsendmailMatch8.7.6
OR
sendmailsendmailMatch8.7.7
OR
sendmailsendmailMatch8.7.8
OR
sendmailsendmailMatch8.7.9
OR
sendmailsendmailMatch8.7.10
OR
sendmailsendmailMatch8.8.8
OR
sendmailsendmailMatch8.9.0
OR
sendmailsendmailMatch8.9.1
OR
sendmailsendmailMatch8.9.2
OR
sendmailsendmailMatch8.9.3
OR
sendmailsendmailMatch8.10
OR
sendmailsendmailMatch8.10.0
OR
sendmailsendmailMatch8.10.1
OR
sendmailsendmailMatch8.10.2
OR
sendmailsendmailMatch8.11.0
OR
sendmailsendmailMatch8.11.1
OR
sendmailsendmailMatch8.11.2
OR
sendmailsendmailMatch8.11.3
OR
sendmailsendmailMatch8.11.4
OR
sendmailsendmailMatch8.11.5
OR
sendmailsendmailMatch8.11.6
OR
sendmailsendmailMatch8.11.7
OR
sendmailsendmailMatch8.12beta10
OR
sendmailsendmailMatch8.12beta12
OR
sendmailsendmailMatch8.12beta16
OR
sendmailsendmailMatch8.12beta5
OR
sendmailsendmailMatch8.12beta7
OR
sendmailsendmailMatch8.12.0
OR
sendmailsendmailMatch8.12.1
OR
sendmailsendmailMatch8.12.2
OR
sendmailsendmailMatch8.12.3
OR
sendmailsendmailMatch8.12.4
OR
sendmailsendmailMatch8.12.5
OR
sendmailsendmailMatch8.12.6
OR
sendmailsendmailMatch8.12.7
OR
sendmailsendmailMatch8.12.8
OR
sendmailsendmailMatch8.12.9
OR
sendmailsendmailMatch8.12.10
OR
sendmailsendmailMatch8.12.11
OR
sendmailsendmailMatch8.13.0

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

8

Confidence

High

EPSS

0.065

Percentile

93.7%