CVE-1999-1109: Medium severity Sendmail Sendmail vulnerability
Published Dec 22, 1999
·Updated
Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, while Sendmail continues to process the commands after the connection has been terminated.
Affected Software
1 affected component
Sendmail Sendmail<=8.10.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Sendmailto a version that resolves this vulnerability.Fixed in 8.10.0
Event History
Dec 22, 1999
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-1999-1109?
CVE-1999-1109 is classified as a denial of service vulnerability.
2
How do I fix CVE-1999-1109?
To mitigate CVE-1999-1109, upgrade Sendmail to version 8.10.1 or later.
3
What versions of Sendmail are affected by CVE-1999-1109?
CVE-1999-1109 affects Sendmail versions before 8.10.0.
4
Can CVE-1999-1109 be exploited remotely?
Yes, CVE-1999-1109 can be exploited by remote attackers sending ETRN commands.
5
What type of attack does CVE-1999-1109 facilitate?
CVE-1999-1109 facilitates a denial of service attack by causing server resource exhaustion.