Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade sendmail | Jul 30, 2024 | Jun 7, 2006 |
| Freebsd | — | Upgrade FreeBSD | Dec 10, 2025 | Jun 14, 2006 |
| Gentoo Linux | — | Upgrade mail-mta/sendmail. | Oct 30, 2017 | Jun 7, 2006 |
| Suse | — | Upgrade sendmail | Feb 17, 2015 | Jun 7, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub