Retired: Sendmail SM_SysLog Remote Memory Leak Denial Of Service Vulnerability
BID:17207
Info
Retired: Sendmail SM_SysLog Remote Memory Leak Denial Of Service Vulnerability
| Bugtraq ID: | 17207 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 23 2006 12:00AM |
| Updated: | Mar 27 2006 03:19AM |
| Credit: | Discovered by Ido Kanner. |
| Vulnerable: |
Sendmail Consortium Sendmail 8.13.5 Sendmail Consortium Sendmail 8.13.3 Sendmail Consortium Sendmail 8.12.11 Sendmail Consortium Sendmail 8.12.10 Sendmail Consortium Sendmail 8.12.9 Sendmail Consortium Sendmail 8.12.8 Sendmail Consortium Sendmail 8.12.7 Sendmail Consortium Sendmail 8.12.6 Sendmail Consortium Sendmail 8.12.5 Sendmail Consortium Sendmail 8.12.4 Sendmail Consortium Sendmail 8.12.3 Sendmail Consortium Sendmail 8.12.2 Sendmail Consortium Sendmail 8.12.1 Sendmail Consortium Sendmail 8.12 beta7 Sendmail Consortium Sendmail 8.12 beta5 Sendmail Consortium Sendmail 8.12 beta16 Sendmail Consortium Sendmail 8.12 beta12 Sendmail Consortium Sendmail 8.12 beta10 Sendmail Consortium Sendmail 8.12 .0 Sendmail Consortium Sendmail 8.11.7 Sendmail Consortium Sendmail 8.11.6 Sendmail Consortium Sendmail 8.11.5 Sendmail Consortium Sendmail 8.11.4 Sendmail Consortium Sendmail 8.11.3 Sendmail Consortium Sendmail 8.11.2 Sendmail Consortium Sendmail 8.11.1 Sendmail Consortium Sendmail 8.11 Sendmail Consortium Sendmail 8.10.2 Sendmail Consortium Sendmail 8.10.1 Sendmail Consortium Sendmail 8.10 Sendmail Consortium Sendmail 8.9.3 Sendmail Consortium Sendmail 8.9.2 Sendmail Consortium Sendmail 8.9.1 Sendmail Consortium Sendmail 8.9 .0 Sendmail Consortium Sendmail 8.8.8 |
| Not Vulnerable: |
Sendmail Consortium Sendmail 8.13.6 |
Discussion
Retired: Sendmail SM_SysLog Remote Memory Leak Denial Of Service Vulnerability
Sendmail is prone to a remote denial-of-service vulnerability. The application fails to properly free allocated memory regions when it is finished with them.
Remote attackers may leverage this issue to consume excessive memory, eventually crashing the application. This will deny further email service to legitimate users.
Sendmail versions prior to 8.13.6 are vulnerable to this issue.
** Update: Due to further analysis and details from the vendor, this BID is retired. Since the memory buffer that was documented as not being freed is a local variable, this is not a vulnerability.
Sendmail is prone to a remote denial-of-service vulnerability. The application fails to properly free allocated memory regions when it is finished with them.
Remote attackers may leverage this issue to consume excessive memory, eventually crashing the application. This will deny further email service to legitimate users.
Sendmail versions prior to 8.13.6 are vulnerable to this issue.
** Update: Due to further analysis and details from the vendor, this BID is retired. Since the memory buffer that was documented as not being freed is a local variable, this is not a vulnerability.
Exploit / POC
Retired: Sendmail SM_SysLog Remote Memory Leak Denial Of Service Vulnerability
An attacker likely exploits this issue with an MTA or with network-scripting utilities.
An attacker likely exploits this issue with an MTA or with network-scripting utilities.
Solution / Fix
Retired: Sendmail SM_SysLog Remote Memory Leak Denial Of Service Vulnerability
Solution:
The vendor has released version 8.13.6 to address this issue.
Sendmail Consortium Sendmail 8.10
Sendmail Consortium Sendmail 8.10.1
Sendmail Consortium Sendmail 8.10.2
Sendmail Consortium Sendmail 8.11
Sendmail Consortium Sendmail 8.11.1
Sendmail Consortium Sendmail 8.11.2
Sendmail Consortium Sendmail 8.11.3
Sendmail Consortium Sendmail 8.11.4
Sendmail Consortium Sendmail 8.11.5
Sendmail Consortium Sendmail 8.11.6
Sendmail Consortium Sendmail 8.11.7
Sendmail Consortium Sendmail 8.12 .0
Sendmail Consortium Sendmail 8.12 beta12
Sendmail Consortium Sendmail 8.12 beta10
Sendmail Consortium Sendmail 8.12 beta5
Sendmail Consortium Sendmail 8.12 beta16
Sendmail Consortium Sendmail 8.12 beta7
Sendmail Consortium Sendmail 8.12.1
Sendmail Consortium Sendmail 8.12.10
Sendmail Consortium Sendmail 8.12.11
Sendmail Consortium Sendmail 8.12.2
Sendmail Consortium Sendmail 8.12.3
Sendmail Consortium Sendmail 8.12.4
Sendmail Consortium Sendmail 8.12.5
Sendmail Consortium Sendmail 8.12.6
Sendmail Consortium Sendmail 8.12.7
Sendmail Consortium Sendmail 8.12.8
Sendmail Consortium Sendmail 8.12.9
Sendmail Consortium Sendmail 8.13.3
Sendmail Consortium Sendmail 8.13.5
Sendmail Consortium Sendmail 8.8.8
Sendmail Consortium Sendmail 8.9 .0
Sendmail Consortium Sendmail 8.9.1
Sendmail Consortium Sendmail 8.9.2
Sendmail Consortium Sendmail 8.9.3
Solution:
The vendor has released version 8.13.6 to address this issue.
Sendmail Consortium Sendmail 8.10
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.10.1
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.10.2
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.11
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.11.1
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.11.2
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.11.3
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.11.4
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.11.5
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.11.6
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.11.7
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.12 .0
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.12 beta12
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.12 beta10
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.12 beta5
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.12 beta16
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.12 beta7
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.12.1
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.12.10
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.12.11
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.12.2
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.12.3
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.12.4
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.12.5
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.12.6
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.12.7
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.12.8
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.12.9
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.13.3
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.13.5
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.8.8
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.9 .0
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.9.1
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.9.2
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
Sendmail Consortium Sendmail 8.9.3
-
Sendmail Consortium Sendmail 8.13.6
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.13.6.tar.gz
References
Retired: Sendmail SM_SysLog Remote Memory Leak Denial Of Service Vulnerability
References:
References:
- Sendmail 8.13.6 (Sendmail Consortium)
- Sendmail Homepage (Sendmail Consortium)
- Sendmail MTA Security Vulnerability (Sendmail)
- Re: SendGate: Sendmail Multiple Vulnerabilities (Race Condition DoS, Memory Jump (Eric Allman
)