First published: Fri Oct 04 2002(Updated: )
Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malicious DNS server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sendmail | =8.12.0 | |
Sendmail | =8.12.1 | |
Sendmail | =8.12.3 | |
Sendmail | =8.12.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0906 is considered a critical vulnerability due to its potential to allow remote code execution and denial of service.
To fix CVE-2002-0906, upgrade to Sendmail version 8.12.5 or later.
Sendmail versions 8.12.0 to 8.12.4 are affected by CVE-2002-0906.
Yes, CVE-2002-0906 can be exploited remotely by attacking the Sendmail service configured to query malicious DNS servers.
CVE-2002-0906 can lead to a denial of service or potentially allow attackers to execute arbitrary code on affected systems.