CVE-2006-0058
Sendmail 8.13.5 - Remote Signal Handling (PoC)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.
Sendmail, Inc. has recently become aware of a security vulnerability in certain versions of sendmail Mail Transfer Agent (MTA) and UNIX and Linux products that contain it. Sendmail was notified by security researchers at ISS that, under some specific timing conditions, this vulnerability may permit a specifically crafted attack to take over the sendmail MTA process, allowing remote attackers to execute commands and run arbitrary programs on the system running the MTA, affecting email delivery, or tampering with other programs and data on this system. Versions 8.13.5 and below are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-01-01 CVE Reserved
- 2006-03-22 CVE Published
- 2006-07-21 First Exploit
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (78)
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/48476 | 2006-07-24 | |
https://www.exploit-db.com/exploits/2051 | 2006-07-21 |
URL | Date | SRC |
---|---|---|
http://www.redhat.com/support/errata/RHSA-2006-0264.html | 2018-10-19 | |
http://www.redhat.com/support/errata/RHSA-2006-0265.html | 2018-10-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sendmail Search vendor "Sendmail" | Sendmail Search vendor "Sendmail" for product "Sendmail" | 8.13.0 Search vendor "Sendmail" for product "Sendmail" and version "8.13.0" | - |
Affected
| ||||||
Sendmail Search vendor "Sendmail" | Sendmail Search vendor "Sendmail" for product "Sendmail" | 8.13.1 Search vendor "Sendmail" for product "Sendmail" and version "8.13.1" | - |
Affected
| ||||||
Sendmail Search vendor "Sendmail" | Sendmail Search vendor "Sendmail" for product "Sendmail" | 8.13.2 Search vendor "Sendmail" for product "Sendmail" and version "8.13.2" | - |
Affected
| ||||||
Sendmail Search vendor "Sendmail" | Sendmail Search vendor "Sendmail" for product "Sendmail" | 8.13.3 Search vendor "Sendmail" for product "Sendmail" and version "8.13.3" | - |
Affected
| ||||||
Sendmail Search vendor "Sendmail" | Sendmail Search vendor "Sendmail" for product "Sendmail" | 8.13.4 Search vendor "Sendmail" for product "Sendmail" and version "8.13.4" | - |
Affected
| ||||||
Sendmail Search vendor "Sendmail" | Sendmail Search vendor "Sendmail" for product "Sendmail" | 8.13.5 Search vendor "Sendmail" for product "Sendmail" and version "8.13.5" | - |
Affected
|