Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.
CVSS Details
- CVSS 3.1 Base Score: 8.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade sendmail | Jul 30, 2024 | Mar 22, 2006 |
| Freebsd | — | Upgrade FreeBSDUpgrade sendmail | Dec 10, 2025 | Mar 24, 2006 |
| Gentoo Linux | — | Upgrade mail-mta/sendmail. | Oct 30, 2017 | Mar 22, 2006 |
| Suse | — | Upgrade sendmail | Feb 17, 2015 | Mar 22, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub