CVE Vulnerabilities

CVE-2009-4565

Published: Jan 04, 2010 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
4 LOW
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

sendmail before 8.14.4 does not properly handle a 0 character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Affected Software

NameVendorStart VersionEnd Version
SendmailSendmail*8.14.3 (including)
SendmailSendmail2.6 (including)2.6 (including)
SendmailSendmail2.6.1 (including)2.6.1 (including)
SendmailSendmail3.0 (including)3.0 (including)
SendmailSendmail3.0.1 (including)3.0.1 (including)
SendmailSendmail4.1 (including)4.1 (including)
SendmailSendmail4.55 (including)4.55 (including)
SendmailSendmail5 (including)5 (including)
SendmailSendmail5.59 (including)5.59 (including)
SendmailSendmail5.61 (including)5.61 (including)
SendmailSendmail5.65 (including)5.65 (including)
SendmailSendmail8.6.7 (including)8.6.7 (including)
SendmailSendmail8.7.6 (including)8.7.6 (including)
SendmailSendmail8.7.7 (including)8.7.7 (including)
SendmailSendmail8.7.8 (including)8.7.8 (including)
SendmailSendmail8.7.9 (including)8.7.9 (including)
SendmailSendmail8.7.10 (including)8.7.10 (including)
SendmailSendmail8.8.8 (including)8.8.8 (including)
SendmailSendmail8.9.0 (including)8.9.0 (including)
SendmailSendmail8.9.1 (including)8.9.1 (including)
SendmailSendmail8.9.2 (including)8.9.2 (including)
SendmailSendmail8.9.3 (including)8.9.3 (including)
SendmailSendmail8.10 (including)8.10 (including)
SendmailSendmail8.10.0 (including)8.10.0 (including)
SendmailSendmail8.10.1 (including)8.10.1 (including)
SendmailSendmail8.10.2 (including)8.10.2 (including)
SendmailSendmail8.11.0 (including)8.11.0 (including)
SendmailSendmail8.11.1 (including)8.11.1 (including)
SendmailSendmail8.11.2 (including)8.11.2 (including)
SendmailSendmail8.11.3 (including)8.11.3 (including)
SendmailSendmail8.11.4 (including)8.11.4 (including)
SendmailSendmail8.11.5 (including)8.11.5 (including)
SendmailSendmail8.11.6 (including)8.11.6 (including)
SendmailSendmail8.11.7 (including)8.11.7 (including)
SendmailSendmail8.12-beta10 (including)8.12-beta10 (including)
SendmailSendmail8.12-beta12 (including)8.12-beta12 (including)
SendmailSendmail8.12-beta16 (including)8.12-beta16 (including)
SendmailSendmail8.12-beta5 (including)8.12-beta5 (including)
SendmailSendmail8.12-beta7 (including)8.12-beta7 (including)
SendmailSendmail8.12.0 (including)8.12.0 (including)
SendmailSendmail8.12.1 (including)8.12.1 (including)
SendmailSendmail8.12.2 (including)8.12.2 (including)
SendmailSendmail8.12.3 (including)8.12.3 (including)
SendmailSendmail8.12.4 (including)8.12.4 (including)
SendmailSendmail8.12.5 (including)8.12.5 (including)
SendmailSendmail8.12.6 (including)8.12.6 (including)
SendmailSendmail8.12.7 (including)8.12.7 (including)
SendmailSendmail8.12.8 (including)8.12.8 (including)
SendmailSendmail8.12.9 (including)8.12.9 (including)
SendmailSendmail8.12.10 (including)8.12.10 (including)
SendmailSendmail8.13.0 (including)8.13.0 (including)
SendmailSendmail8.13.1 (including)8.13.1 (including)
SendmailSendmail8.13.1.2 (including)8.13.1.2 (including)
SendmailSendmail8.13.2 (including)8.13.2 (including)
SendmailSendmail8.13.3 (including)8.13.3 (including)
SendmailSendmail8.13.4 (including)8.13.4 (including)
SendmailSendmail8.13.5 (including)8.13.5 (including)
SendmailSendmail8.13.6 (including)8.13.6 (including)
SendmailSendmail8.13.7 (including)8.13.7 (including)
SendmailSendmail8.13.8 (including)8.13.8 (including)
SendmailSendmail8.14.1 (including)8.14.1 (including)
SendmailSendmail8.14.2 (including)8.14.2 (including)
Red Hat Enterprise Linux 4RedHatsendmail-0:8.13.1-6.el4*
Red Hat Enterprise Linux 5RedHatsendmail-0:8.13.8-8.el5*
SendmailUbuntudapper*
SendmailUbuntuhardy*
SendmailUbuntuintrepid*
SendmailUbuntujaunty*
SendmailUbuntukarmic*
SendmailUbuntuupstream*

References