CVE-2002-0906: Buffer Overflow
Published Oct 4, 2002
·Updated
Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malicious DNS server.
Affected Software
4 affected components
Sendmail Sendmail=8.12.0
Sendmail Sendmail=8.12.1
Sendmail Sendmail=8.12.3
Sendmail Sendmail=8.12.4
Remediation
Patch Available
Event History
Oct 4, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0906?
CVE-2002-0906 is considered a critical vulnerability due to its potential to allow remote code execution and denial of service.
2
How do I fix CVE-2002-0906?
To fix CVE-2002-0906, upgrade to Sendmail version 8.12.5 or later.
3
What versions of Sendmail are affected by CVE-2002-0906?
Sendmail versions 8.12.0 to 8.12.4 are affected by CVE-2002-0906.
4
Can CVE-2002-0906 be exploited remotely?
Yes, CVE-2002-0906 can be exploited remotely by attacking the Sendmail service configured to query malicious DNS servers.
5
What impact does CVE-2002-0906 have on systems?
CVE-2002-0906 can lead to a denial of service or potentially allow attackers to execute arbitrary code on affected systems.