CVE-2009-1490

Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
VendorProductVersion
sendmailsendmail
𝑥
≤ 8.13.1.2
sendmailsendmail
2.6
sendmailsendmail
2.6
sendmailsendmail
2.6.1
sendmailsendmail
2.6.1
sendmailsendmail
2.6.2
sendmailsendmail
3.0
sendmailsendmail
3.0
sendmailsendmail
3.0.1
sendmailsendmail
3.0.1
sendmailsendmail
3.0.2
sendmailsendmail
3.0.2
sendmailsendmail
3.0.3
sendmailsendmail
4.1
sendmailsendmail
4.55
sendmailsendmail
5.59
sendmailsendmail
5.61
sendmailsendmail
5.65
sendmailsendmail
8.6.7
sendmailsendmail
8.7.6
sendmailsendmail
8.7.7
sendmailsendmail
8.7.8
sendmailsendmail
8.7.9
sendmailsendmail
8.7.10
sendmailsendmail
8.8.8
sendmailsendmail
8.9.0
sendmailsendmail
8.9.1
sendmailsendmail
8.9.2
sendmailsendmail
8.9.3
sendmailsendmail
8.10
sendmailsendmail
8.10.0
sendmailsendmail
8.10.1
sendmailsendmail
8.10.2
sendmailsendmail
8.11.0
sendmailsendmail
8.11.1
sendmailsendmail
8.11.2
sendmailsendmail
8.11.3
sendmailsendmail
8.11.4
sendmailsendmail
8.11.5
sendmailsendmail
8.11.6
sendmailsendmail
8.11.7
sendmailsendmail
8.12:beta10
sendmailsendmail
8.12:beta12
sendmailsendmail
8.12:beta16
sendmailsendmail
8.12:beta5
sendmailsendmail
8.12:beta7
sendmailsendmail
8.12.0
sendmailsendmail
8.12.1
sendmailsendmail
8.12.2
sendmailsendmail
8.12.3
sendmailsendmail
8.12.4
sendmailsendmail
8.12.5
sendmailsendmail
8.12.6
sendmailsendmail
8.12.7
sendmailsendmail
8.12.8
sendmailsendmail
8.12.9
sendmailsendmail
8.12.10
sendmailsendmail
8.12.11
sendmailsendmail
8.13.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
sendmail
bullseye
8.15.2-22+deb11u3
fixed
bookworm
8.17.1.9-2+deb12u2
fixed
sid
8.18.1-6
fixed
trixie
8.18.1-6
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sendmail
jaunty
not-affected
intrepid
not-affected
hardy
not-affected
dapper
not-affected