CVE Vulnerabilities

CVE-2009-4565

Published: Jan 04, 2010 | Modified: Sep 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
4 LOW
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

sendmail before 8.14.4 does not properly handle a 0 character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Affected Software

Name Vendor Start Version End Version
Sendmail Sendmail * 8.14.3 (including)
Sendmail Sendmail 2.6 (including) 2.6 (including)
Sendmail Sendmail 2.6.1 (including) 2.6.1 (including)
Sendmail Sendmail 3.0 (including) 3.0 (including)
Sendmail Sendmail 3.0.1 (including) 3.0.1 (including)
Sendmail Sendmail 4.1 (including) 4.1 (including)
Sendmail Sendmail 4.55 (including) 4.55 (including)
Sendmail Sendmail 5 (including) 5 (including)
Sendmail Sendmail 5.59 (including) 5.59 (including)
Sendmail Sendmail 5.61 (including) 5.61 (including)
Sendmail Sendmail 5.65 (including) 5.65 (including)
Sendmail Sendmail 8.6.7 (including) 8.6.7 (including)
Sendmail Sendmail 8.7.6 (including) 8.7.6 (including)
Sendmail Sendmail 8.7.7 (including) 8.7.7 (including)
Sendmail Sendmail 8.7.8 (including) 8.7.8 (including)
Sendmail Sendmail 8.7.9 (including) 8.7.9 (including)
Sendmail Sendmail 8.7.10 (including) 8.7.10 (including)
Sendmail Sendmail 8.8.8 (including) 8.8.8 (including)
Sendmail Sendmail 8.9.0 (including) 8.9.0 (including)
Sendmail Sendmail 8.9.1 (including) 8.9.1 (including)
Sendmail Sendmail 8.9.2 (including) 8.9.2 (including)
Sendmail Sendmail 8.9.3 (including) 8.9.3 (including)
Sendmail Sendmail 8.10 (including) 8.10 (including)
Sendmail Sendmail 8.10.0 (including) 8.10.0 (including)
Sendmail Sendmail 8.10.1 (including) 8.10.1 (including)
Sendmail Sendmail 8.10.2 (including) 8.10.2 (including)
Sendmail Sendmail 8.11.0 (including) 8.11.0 (including)
Sendmail Sendmail 8.11.1 (including) 8.11.1 (including)
Sendmail Sendmail 8.11.2 (including) 8.11.2 (including)
Sendmail Sendmail 8.11.3 (including) 8.11.3 (including)
Sendmail Sendmail 8.11.4 (including) 8.11.4 (including)
Sendmail Sendmail 8.11.5 (including) 8.11.5 (including)
Sendmail Sendmail 8.11.6 (including) 8.11.6 (including)
Sendmail Sendmail 8.11.7 (including) 8.11.7 (including)
Sendmail Sendmail 8.12-beta10 (including) 8.12-beta10 (including)
Sendmail Sendmail 8.12-beta12 (including) 8.12-beta12 (including)
Sendmail Sendmail 8.12-beta16 (including) 8.12-beta16 (including)
Sendmail Sendmail 8.12-beta5 (including) 8.12-beta5 (including)
Sendmail Sendmail 8.12-beta7 (including) 8.12-beta7 (including)
Sendmail Sendmail 8.12.0 (including) 8.12.0 (including)
Sendmail Sendmail 8.12.1 (including) 8.12.1 (including)
Sendmail Sendmail 8.12.2 (including) 8.12.2 (including)
Sendmail Sendmail 8.12.3 (including) 8.12.3 (including)
Sendmail Sendmail 8.12.4 (including) 8.12.4 (including)
Sendmail Sendmail 8.12.5 (including) 8.12.5 (including)
Sendmail Sendmail 8.12.6 (including) 8.12.6 (including)
Sendmail Sendmail 8.12.7 (including) 8.12.7 (including)
Sendmail Sendmail 8.12.8 (including) 8.12.8 (including)
Sendmail Sendmail 8.12.9 (including) 8.12.9 (including)
Sendmail Sendmail 8.12.10 (including) 8.12.10 (including)
Sendmail Sendmail 8.13.0 (including) 8.13.0 (including)
Sendmail Sendmail 8.13.1 (including) 8.13.1 (including)
Sendmail Sendmail 8.13.1.2 (including) 8.13.1.2 (including)
Sendmail Sendmail 8.13.2 (including) 8.13.2 (including)
Sendmail Sendmail 8.13.3 (including) 8.13.3 (including)
Sendmail Sendmail 8.13.4 (including) 8.13.4 (including)
Sendmail Sendmail 8.13.5 (including) 8.13.5 (including)
Sendmail Sendmail 8.13.6 (including) 8.13.6 (including)
Sendmail Sendmail 8.13.7 (including) 8.13.7 (including)
Sendmail Sendmail 8.13.8 (including) 8.13.8 (including)
Sendmail Sendmail 8.14.1 (including) 8.14.1 (including)
Sendmail Sendmail 8.14.2 (including) 8.14.2 (including)
Red Hat Enterprise Linux 4 RedHat sendmail-0:8.13.1-6.el4 *
Red Hat Enterprise Linux 5 RedHat sendmail-0:8.13.8-8.el5 *
Sendmail Ubuntu dapper *
Sendmail Ubuntu hardy *
Sendmail Ubuntu intrepid *
Sendmail Ubuntu jaunty *
Sendmail Ubuntu karmic *
Sendmail Ubuntu upstream *

References