Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.

Project Subscriptions

Vendors Products
Enterprise Linux Subscribe
Sendmail Subscribe
Sendmail Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-1015-1 New sendmail packages fix arbitrary code execution
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:13.sendmail.asc cve-icon cve-icon
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-010.txt.asc cve-icon cve-icon
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.24/SCOSA-2006.24.txt cve-icon cve-icon
ftp://patches.sgi.com/support/free/security/advisories/20060302-01-P cve-icon cve-icon
ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U cve-icon cve-icon
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00629555 cve-icon cve-icon
http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635 cve-icon cve-icon
http://secunia.com/advisories/19342 cve-icon cve-icon
http://secunia.com/advisories/19345 cve-icon cve-icon
http://secunia.com/advisories/19346 cve-icon cve-icon
http://secunia.com/advisories/19349 cve-icon cve-icon
http://secunia.com/advisories/19356 cve-icon cve-icon
http://secunia.com/advisories/19360 cve-icon cve-icon
http://secunia.com/advisories/19361 cve-icon cve-icon
http://secunia.com/advisories/19363 cve-icon cve-icon
http://secunia.com/advisories/19367 cve-icon cve-icon
http://secunia.com/advisories/19368 cve-icon cve-icon
http://secunia.com/advisories/19394 cve-icon cve-icon
http://secunia.com/advisories/19404 cve-icon cve-icon
http://secunia.com/advisories/19407 cve-icon cve-icon
http://secunia.com/advisories/19450 cve-icon cve-icon
http://secunia.com/advisories/19466 cve-icon cve-icon
http://secunia.com/advisories/19532 cve-icon cve-icon
http://secunia.com/advisories/19533 cve-icon cve-icon
http://secunia.com/advisories/19676 cve-icon cve-icon
http://secunia.com/advisories/19774 cve-icon cve-icon
http://secunia.com/advisories/20243 cve-icon cve-icon
http://secunia.com/advisories/20723 cve-icon cve-icon
http://securityreason.com/securityalert/612 cve-icon cve-icon
http://securityreason.com/securityalert/743 cve-icon cve-icon
http://securitytracker.com/id?1015801 cve-icon cve-icon
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.619600 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102262-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102324-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200494-1 cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2006-074.htm cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm cve-icon cve-icon
http://www-1.ibm.com/support/search.wss?rs=0&q=IY82992&apar=only cve-icon cve-icon
http://www-1.ibm.com/support/search.wss?rs=0&q=IY82993&apar=only cve-icon cve-icon
http://www-1.ibm.com/support/search.wss?rs=0&q=IY82994&apar=only cve-icon cve-icon
http://www.ciac.org/ciac/bulletins/q-151.shtml cve-icon cve-icon
http://www.debian.org/security/2006/dsa-1015 cve-icon cve-icon
http://www.f-secure.com/security/fsc-2006-2.shtml cve-icon cve-icon
http://www.gentoo.org/security/en/glsa/glsa-200603-21.xml cve-icon cve-icon
http://www.iss.net/threats/216.html cve-icon cve-icon
http://www.kb.cert.org/vuls/id/834865 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2006:058 cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2006_17_sendmail.html cve-icon cve-icon
http://www.openbsd.org/errata38.html#sendmail cve-icon cve-icon
http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.007-sendmail.html cve-icon cve-icon
http://www.osvdb.org/24037 cve-icon cve-icon
http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00017.html cve-icon cve-icon
http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00018.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2006-0264.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2006-0265.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/428536/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/428656/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/17192 cve-icon cve-icon
http://www.sendmail.com/company/advisory/index.shtml cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA06-081A.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/1049 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/1051 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/1068 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/1072 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/1139 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/1157 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/1529 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/2189 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/2490 cve-icon cve-icon
http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688 cve-icon cve-icon
http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=2751 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/24584 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2006-0058 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11074 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1689 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2006-0058 cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2024-08-07T16:18:20.809Z

Reserved: 2006-01-01T05:00:00.000Z

Link: CVE-2006-0058

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2006-03-22T20:06:00.000

Modified: 2025-04-03T01:03:51.193

Link: CVE-2006-0058

cve-icon Redhat

Severity : Critical

Publid Date: 2006-03-22T16:00:00Z

Links: CVE-2006-0058 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses