The DNS map code in Sendmail 8.12.8 and earlier, when using the enhdnsbl feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sendmail | Redhat | 8.12.8-4 | 8.12.8-4 |
Sendmail | Redhat | 8.12.5-7 | 8.12.5-7 |
Sendmail | Sendmail | 8.12.3 | 8.12.3 |
Sendmail | Sendmail | 8.12.8 | 8.12.8 |
Irix | Sgi | 6.5.21 | 6.5.21 |
Irix | Sgi | 6.5.19 | 6.5.19 |
Sendmail | Sendmail | 8.12.4 | 8.12.4 |
Irix | Sgi | 6.5.20 | 6.5.20 |
Sendmail | Sendmail | 8.12.1 | 8.12.1 |
Sendmail | Redhat | 8.12.8-4 | 8.12.8-4 |
Sendmail | Redhat | 8.12.8-4 | 8.12.8-4 |
Sendmail | Redhat | 8.12.5-7 | 8.12.5-7 |
Sendmail | Redhat | 8.12.5-7 | 8.12.5-7 |
Sendmail | Sendmail | 8.12.5 | 8.12.5 |
Sendmail | Redhat | 8.12.5-7 | 8.12.5-7 |
Sendmail | Sendmail | 8.12.2 | 8.12.2 |
Sendmail | Redhat | 8.12.8-4 | 8.12.8-4 |
Sendmail | Sendmail | 8.12.6 | 8.12.6 |
Sendmail | Sendmail | 8.12.7 | 8.12.7 |