CVE-2006-4434
Last modified
CVE-2006-4434 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... EPSS estimates a 4.33% chance of exploitation in the next 30 days.
Description
Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected."
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sendmail | Sendmail | < 8.13.8 |
References
- http://secunia.com/advisories/21637Broken Link, Patch, Vendor Advisory
- http://secunia.com/advisories/21641Broken Link, Patch, Vendor Advisory
- http://secunia.com/advisories/21696Broken Link, Vendor Advisory
- http://secunia.com/advisories/21700Broken Link, Vendor Advisory
- http://secunia.com/advisories/21749Broken Link, Vendor Advisory
- http://secunia.com/advisories/22369Broken Link, Vendor Advisory
- http://securitytracker.com/id?1016753Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.debian.org/security/2006/dsa-1164Broken Link
- http://www.openbsd.org/errata.html#sendmail3Release Notes
- http://www.openbsd.org/errata38.html#sendmail3Third Party Advisory
- http://www.osvdb.org/28193Broken Link
- http://www.securityfocus.com/bid/19714Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.sendmail.org/releases/8.13.8.htmlRelease Notes
- http://www.vupen.com/english/advisories/2006/3393Broken Link, Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3994Broken Link, Vendor Advisory
- http://secunia.com/advisories/21637Broken Link, Patch, Vendor Advisory
- http://secunia.com/advisories/21641Broken Link, Patch, Vendor Advisory
- http://secunia.com/advisories/21696Broken Link, Vendor Advisory
- http://secunia.com/advisories/21700Broken Link, Vendor Advisory
- http://secunia.com/advisories/21749Broken Link, Vendor Advisory
- http://secunia.com/advisories/22369Broken Link, Vendor Advisory
- http://securitytracker.com/id?1016753Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.debian.org/security/2006/dsa-1164Broken Link
- http://www.openbsd.org/errata.html#sendmail3Release Notes
- http://www.openbsd.org/errata38.html#sendmail3Third Party Advisory
- http://www.osvdb.org/28193Broken Link
- http://www.securityfocus.com/bid/19714Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.sendmail.org/releases/8.13.8.htmlRelease Notes
- http://www.vupen.com/english/advisories/2006/3393Broken Link, Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3994Broken Link, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-4434?
How severe is CVE-2006-4434?
How do I fix CVE-2006-4434?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-4428PHP remote file inclusion vulnerability in index.php in Jupi…9.8
- CVE-2006-4429PHP remote file inclusion vulnerability in handlers/email/mo…
- CVE-2006-4430The Cisco Network Admission Control (NAC) 3.6.4.1 and earlie…
- CVE-2006-4431Multiple buffer overflows in the (a) Session Clustering Daem…
- CVE-2006-4432Directory traversal vulnerability in Zend Platform 2.2.1 and…
- CVE-2006-4433PHP before 4.4.3 and 5.x before 5.1.4 does not limit the cha…
- CVE-2006-4435OpenBSD 3.8, 3.9, and possibly earlier versions allows conte…
- CVE-2006-4436isakmpd in OpenBSD 3.8, 3.9, and possibly earlier versions, …
- CVE-2006-4437Eval injection vulnerability in Tagger LE allows remote atta…
- CVE-2006-4438Heap-based buffer overflow in SpIDer for Dr.Web Scanner for …
- CVE-2006-4439pkgadd in Sun Solaris 10 before 20060825 installs files with…
- CVE-2006-4440PHP remote file inclusion vulnerability in main.php in Ay Sy…
Are you affected by CVE-2006-4434?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
