sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade sendmail | Jul 30, 2024 | Jan 4, 2010 |
| Gentoo Linux | — | Upgrade mail-mta/sendmail. | Oct 30, 2017 | Jan 4, 2010 |
| Hpux | — | Update SMAIL-UPGRADE.INET2-SMAIL to the latest versionUpdate SMAIL-UPGRADE.INET-SMAIL to the latest versionUpdate Sendmail.SENDMAIL-RUN to the latest versionUpdate Sendmail.SENDMAIL-AUX to the latest versionUpdate SMAIL-UPGRADE.INETSVCS-SMAIL to the latest version | Aug 11, 2017 | Jan 4, 2010 |
| Ibm Aix | — | Apply the fix or workaround for sendmail_advisory | Nov 30, 2017 | Jan 4, 2010 |
| Oracle_linux | — | Upgrade sendmail-cfUpgrade sendmailUpgrade sendmail-docUpgrade sendmail-devel | Oct 16, 2024 | Jan 4, 2010 |
| Sendmail | — | Upgrade to the latest version of Sendmail. | Jun 5, 2014 | Jan 4, 2010 |
| Suse | — | Upgrade uucpUpgrade sap-aio-releaseUpgrade rmailUpgrade sendmail-develUpgrade sendmail | Feb 17, 2015 | Jan 4, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub