Sendmail SMTP HELO Argument Buffer Overflow Vulnerability
BID:49431
Info
Sendmail SMTP HELO Argument Buffer Overflow Vulnerability
| Bugtraq ID: | 49431 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-1999-0098 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 01 1998 12:00AM |
| Updated: | Apr 01 1998 12:00AM |
| Credit: | rootshell.com |
| Vulnerable: |
Sendmail Consortium Sendmail 8.14.4 Sendmail Consortium Sendmail 8.14.3 Sendmail Consortium Sendmail 8.13.8 Sendmail Consortium Sendmail 8.13.7 Sendmail Consortium Sendmail 8.13.6 Sendmail Consortium Sendmail 8.13.5 Sendmail Consortium Sendmail 8.13.4 Sendmail Consortium Sendmail 8.13.3 Sendmail Consortium Sendmail 8.13.2 Sendmail Consortium Sendmail 8.13.1 Sendmail Consortium Sendmail 8.12.11 Sendmail Consortium Sendmail 8.12.10 Sendmail Consortium Sendmail 8.12.9 Sendmail Consortium Sendmail 8.12.8 Sendmail Consortium Sendmail 8.12.7 Sendmail Consortium Sendmail 8.12.6 Sendmail Consortium Sendmail 8.12.5 Sendmail Consortium Sendmail 8.12.4 Sendmail Consortium Sendmail 8.12.3 Sendmail Consortium Sendmail 8.12.2 Sendmail Consortium Sendmail 8.12.1 Sendmail Consortium Sendmail 8.12 beta7 Sendmail Consortium Sendmail 8.12 beta5 Sendmail Consortium Sendmail 8.12 beta16 Sendmail Consortium Sendmail 8.12 beta12 Sendmail Consortium Sendmail 8.12 beta10 Sendmail Consortium Sendmail 8.12 .0 Sendmail Consortium Sendmail 8.11.7 Sendmail Consortium Sendmail 8.11.6 Sendmail Consortium Sendmail 8.11.5 Sendmail Consortium Sendmail 8.11.4 Sendmail Consortium Sendmail 8.11.3 Sendmail Consortium Sendmail 8.11.2 Sendmail Consortium Sendmail 8.11.1 Sendmail Consortium Sendmail 8.11 Sendmail Consortium Sendmail 8.10.2 Sendmail Consortium Sendmail 8.10.1 Sendmail Consortium Sendmail 8.10 Sendmail Consortium Sendmail 8.8.8 Sendmail Consortium Sendmail 5.65 Sendmail Consortium Sendmail 5.61 Sendmail Consortium Sendmail 5.59 Sendmail Consortium Sendmail 4.55 Sendmail Consortium Sendmail 4.1 Eric Allman Sendmail 8.11 Eric Allman Sendmail 8.10.1 Eric Allman Sendmail 8.10 Eric Allman Sendmail 8.8.5 Eric Allman Sendmail 8.8.4 Eric Allman Sendmail 8.8.3 Eric Allman Sendmail 8.8.2 Eric Allman Sendmail 8.8.1 Eric Allman Sendmail 8.8 .x Eric Allman Sendmail 8.8 Eric Allman Sendmail 8.7.6 Eric Allman Sendmail 8.7.5 Eric Allman Sendmail 8.7.4 Eric Allman Sendmail 8.7.3 Eric Allman Sendmail 8.7.2 Eric Allman Sendmail 8.7.1 Eric Allman Sendmail 8.7 .x Eric Allman Sendmail 8.6.10 Eric Allman Sendmail 8.6.9 Eric Allman Sendmail 8.6 .x Eric Allman Sendmail 5.59 Eric Allman Sendmail 5.58 |
| Not Vulnerable: |
Sendmail Consortium Sendmail 8.9 .0 |
Discussion
Sendmail SMTP HELO Argument Buffer Overflow Vulnerability
Sendmail is prone to an SMTP HELO command argument buffer overflow vulnerability.
The issue presents itself due to insufficient bounds checking performed when handling malicious SMTP HELO command arguments of excessive length. A remote attacker may exploit this condition to trigger a denial-of-service in the affected daemon.
Sendmail 8.8.8 is affected; earlier versions may also be vulnerable.
Sendmail is prone to an SMTP HELO command argument buffer overflow vulnerability.
The issue presents itself due to insufficient bounds checking performed when handling malicious SMTP HELO command arguments of excessive length. A remote attacker may exploit this condition to trigger a denial-of-service in the affected daemon.
Sendmail 8.8.8 is affected; earlier versions may also be vulnerable.
Exploit / POC
Sendmail SMTP HELO Argument Buffer Overflow Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
Sendmail SMTP HELO Argument Buffer Overflow Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Sendmail SMTP HELO Argument Buffer Overflow Vulnerability
References:
References:
- about sendmail 8.8.8 HELO hole (Valentin Pavlov)
- about sendmail 8.8.8 HELO hole (Gregory Neil Shapiro)