Lucene search

K
nvd[email protected]NVD:CVE-2009-4565
HistoryJan 04, 2010 - 9:30 p.m.

CVE-2009-4565

2010-01-0421:30:00
CWE-310
web.nvd.nist.gov
1

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.4 Medium

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.4%

sendmail before 8.14.4 does not properly handle a ‘\0’ character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Affected configurations

NVD
Node
sendmailsendmailRange8.14.3
OR
sendmailsendmailMatch2.6
OR
sendmailsendmailMatch2.6.1
OR
sendmailsendmailMatch3.0
OR
sendmailsendmailMatch3.0.1
OR
sendmailsendmailMatch4.1
OR
sendmailsendmailMatch4.55
OR
sendmailsendmailMatch5
OR
sendmailsendmailMatch5.59
OR
sendmailsendmailMatch5.61
OR
sendmailsendmailMatch5.65
OR
sendmailsendmailMatch8.6.7
OR
sendmailsendmailMatch8.7.6
OR
sendmailsendmailMatch8.7.7
OR
sendmailsendmailMatch8.7.8
OR
sendmailsendmailMatch8.7.9
OR
sendmailsendmailMatch8.7.10
OR
sendmailsendmailMatch8.8.8
OR
sendmailsendmailMatch8.9.0
OR
sendmailsendmailMatch8.9.1
OR
sendmailsendmailMatch8.9.2
OR
sendmailsendmailMatch8.9.3
OR
sendmailsendmailMatch8.10
OR
sendmailsendmailMatch8.10.0
OR
sendmailsendmailMatch8.10.1
OR
sendmailsendmailMatch8.10.2
OR
sendmailsendmailMatch8.11.0
OR
sendmailsendmailMatch8.11.1
OR
sendmailsendmailMatch8.11.2
OR
sendmailsendmailMatch8.11.3
OR
sendmailsendmailMatch8.11.4
OR
sendmailsendmailMatch8.11.5
OR
sendmailsendmailMatch8.11.6
OR
sendmailsendmailMatch8.11.7
OR
sendmailsendmailMatch8.12beta10
OR
sendmailsendmailMatch8.12beta12
OR
sendmailsendmailMatch8.12beta16
OR
sendmailsendmailMatch8.12beta5
OR
sendmailsendmailMatch8.12beta7
OR
sendmailsendmailMatch8.12.0
OR
sendmailsendmailMatch8.12.1
OR
sendmailsendmailMatch8.12.2
OR
sendmailsendmailMatch8.12.3
OR
sendmailsendmailMatch8.12.4
OR
sendmailsendmailMatch8.12.5
OR
sendmailsendmailMatch8.12.6
OR
sendmailsendmailMatch8.12.7
OR
sendmailsendmailMatch8.12.8
OR
sendmailsendmailMatch8.12.9
OR
sendmailsendmailMatch8.12.10
OR
sendmailsendmailMatch8.13.0
OR
sendmailsendmailMatch8.13.1
OR
sendmailsendmailMatch8.13.1.2
OR
sendmailsendmailMatch8.13.2
OR
sendmailsendmailMatch8.13.3
OR
sendmailsendmailMatch8.13.4
OR
sendmailsendmailMatch8.13.5
OR
sendmailsendmailMatch8.13.6
OR
sendmailsendmailMatch8.13.7
OR
sendmailsendmailMatch8.13.8
OR
sendmailsendmailMatch8.14.1
OR
sendmailsendmailMatch8.14.2

References

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.4 Medium

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.4%