CVE-2009-1490

EUVD-2009-1487
Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
sendmailsendmail
𝑥
≤ 8.13.1.2
sendmailsendmail
2.6
sendmailsendmail
2.6
sendmailsendmail
2.6.1
sendmailsendmail
2.6.1
sendmailsendmail
2.6.2
sendmailsendmail
3.0
sendmailsendmail
3.0
sendmailsendmail
3.0.1
sendmailsendmail
3.0.1
sendmailsendmail
3.0.2
sendmailsendmail
3.0.2
sendmailsendmail
3.0.3
sendmailsendmail
4.1
sendmailsendmail
4.55
sendmailsendmail
5.59
sendmailsendmail
5.61
sendmailsendmail
5.65
sendmailsendmail
8.6.7
sendmailsendmail
8.7.6
sendmailsendmail
8.7.7
sendmailsendmail
8.7.8
sendmailsendmail
8.7.9
sendmailsendmail
8.7.10
sendmailsendmail
8.8.8
sendmailsendmail
8.9.0
sendmailsendmail
8.9.1
sendmailsendmail
8.9.2
sendmailsendmail
8.9.3
sendmailsendmail
8.10
sendmailsendmail
8.10.0
sendmailsendmail
8.10.1
sendmailsendmail
8.10.2
sendmailsendmail
8.11.0
sendmailsendmail
8.11.1
sendmailsendmail
8.11.2
sendmailsendmail
8.11.3
sendmailsendmail
8.11.4
sendmailsendmail
8.11.5
sendmailsendmail
8.11.6
sendmailsendmail
8.11.7
sendmailsendmail
8.12:beta10
sendmailsendmail
8.12:beta12
sendmailsendmail
8.12:beta16
sendmailsendmail
8.12:beta5
sendmailsendmail
8.12:beta7
sendmailsendmail
8.12.0
sendmailsendmail
8.12.1
sendmailsendmail
8.12.2
sendmailsendmail
8.12.3
sendmailsendmail
8.12.4
sendmailsendmail
8.12.5
sendmailsendmail
8.12.6
sendmailsendmail
8.12.7
sendmailsendmail
8.12.8
sendmailsendmail
8.12.9
sendmailsendmail
8.12.10
sendmailsendmail
8.12.11
sendmailsendmail
8.13.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
sendmail
bookworm
8.17.1.9-2+deb12u2
fixed
bullseye
8.15.2-22+deb11u3
fixed
sid
8.18.1-6
fixed
trixie
8.18.1-6
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sendmail
dapper
not-affected
hardy
not-affected
intrepid
not-affected
jaunty
not-affected