CVE Vulnerabilities

CVE-2009-4565

Published: Jan 04, 2010 | Modified: Sep 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

sendmail before 8.14.4 does not properly handle a 0 character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Affected Software

Name Vendor Start Version End Version
Sendmail Sendmail 8.9.2 8.9.2
Sendmail Sendmail 8.11.4 8.11.4
Sendmail Sendmail 8.13.4 8.13.4
Sendmail Sendmail 8.8.8 8.8.8
Sendmail Sendmail 8.11.7 8.11.7
Sendmail Sendmail 8.13.1 8.13.1
Sendmail Sendmail 8.12 8.12
Sendmail Sendmail 5 5
Sendmail Sendmail 2.6 2.6
Sendmail Sendmail 8.11.1 8.11.1
Sendmail Sendmail 8.11.0 8.11.0
Sendmail Sendmail 8.13.5 8.13.5
Sendmail Sendmail 8.12.3 8.12.3
Sendmail Sendmail 8.13.8 8.13.8
Sendmail Sendmail 8.11.3 8.11.3
Sendmail Sendmail 2.6.1 2.6.1
Sendmail Sendmail 8.12.8 8.12.8
Sendmail Sendmail 8.6.7 8.6.7
Sendmail Sendmail 8.7.9 8.7.9
Sendmail Sendmail 5.59 5.59
Sendmail Sendmail 5.61 5.61
Sendmail Sendmail 8.12.9 8.12.9
Sendmail Sendmail 8.9.1 8.9.1
Sendmail Sendmail 8.10.2 8.10.2
Sendmail Sendmail 8.12.4 8.12.4
Sendmail Sendmail 8.12 8.12
Sendmail Sendmail 8.13.6 8.13.6
Sendmail Sendmail 8.9.0 8.9.0
Sendmail Sendmail 8.14.2 8.14.2
Sendmail Sendmail 8.10.1 8.10.1
Sendmail Sendmail 8.7.10 8.7.10
Sendmail Sendmail 8.12.1 8.12.1
Sendmail Sendmail 8.13.7 8.13.7
Sendmail Sendmail 5.65 5.65
Sendmail Sendmail 4.55 4.55
Sendmail Sendmail 8.11.6 8.11.6
Sendmail Sendmail 8.12.5 8.12.5
Sendmail Sendmail 8.7.8 8.7.8
Sendmail Sendmail 8.13.1.2 8.13.1.2
Sendmail Sendmail 8.10 8.10
Sendmail Sendmail 8.12 8.12
Sendmail Sendmail * 8.14.3
Sendmail Sendmail 8.9.3 8.9.3
Sendmail Sendmail 8.12.0 8.12.0
Sendmail Sendmail 4.1 4.1
Sendmail Sendmail 8.14.1 8.14.1
Sendmail Sendmail 8.10.0 8.10.0
Sendmail Sendmail 8.12 8.12
Sendmail Sendmail 8.12.6 8.12.6
Sendmail Sendmail 8.7.6 8.7.6
Sendmail Sendmail 8.12 8.12
Sendmail Sendmail 8.12.2 8.12.2
Sendmail Sendmail 3.0 3.0
Sendmail Sendmail 8.11.2 8.11.2
Sendmail Sendmail 3.0.1 3.0.1
Sendmail Sendmail 8.13.0 8.13.0
Sendmail Sendmail 8.12.7 8.12.7
Sendmail Sendmail 8.7.7 8.7.7
Sendmail Sendmail 8.12.10 8.12.10
Sendmail Sendmail 8.11.5 8.11.5
Sendmail Sendmail 8.13.3 8.13.3
Sendmail Sendmail 8.13.2 8.13.2

References