CVE-1999-0393: Medium severity Eric Allman Sendmail vulnerability
Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Sendmailfrom your environment.If Sendmail is not required, uninstall or replace it with an alternative MTA to eliminate exposure to this vulnerability.
- Compensating control
At the mail gateway or network perimeter, filter or reject incoming SMTP messages that contain an unusually large number of headers (or otherwise appear to include excessive headers) to prevent remote denial-of-service attempts against Sendmail until a patch is available.
- Operational
Monitor Sendmail instances for signs of denial-of-service (service crashes, high resource usage, loss of mail delivery) and collect relevant logs and crash dumps for investigation and recovery while mitigations remain in place.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0393?
CVE-1999-0393 has a severity rating that indicates it can lead to denial of service issues in affected versions of Sendmail.
How do I fix CVE-1999-0393?
To mitigate CVE-1999-0393, upgrade to a patched version of Sendmail that addresses the issue.
Which versions of Sendmail are affected by CVE-1999-0393?
CVE-1999-0393 affects Sendmail versions 8.8.x and 8.9.2.
Can CVE-1999-0393 be exploited remotely?
Yes, CVE-1999-0393 can be exploited remotely by sending specially crafted messages to the vulnerable Sendmail server.
What kind of attack does CVE-1999-0393 enable?
CVE-1999-0393 enables a denial of service attack that can disrupt email services.