Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24028
HistoryApr 10, 2020 - 12:44 a.m.

Authorization Bypass

2020-04-1000:44:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.005 Low

EPSS

Percentile

77.4%

sendmail is vulnerable to authorization bypass. The vulnerability exists as a flaw was found in the way sendmail handled NUL characters in the CommonName field of X.509 certificates. An attacker able to get a carefully-crafted certificate signed by a trusted Certificate Authority could trick sendmail into accepting it by mistake, allowing the attacker to perform a man-in-the-middle attack or bypass intended client certificate authentication.

References