CVE-2005-2070: Medium severity Sendmail Sendmail vulnerability
Published Jun 29, 2005
·Updated
The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a denial of service by keeping an open connection, which prevents ClamAV from reloading.
Affected Software
33 affected components
Sendmail Sendmail=8.8.8
Sendmail Sendmail=8.9.0
Sendmail Sendmail=8.9.1
Sendmail Sendmail=8.9.2
Sendmail Sendmail=8.9.3
Sendmail Sendmail=8.10
Sendmail Sendmail=8.10.1
Sendmail Sendmail=8.10.2
Sendmail Sendmail=8.11.0
Sendmail Sendmail=8.11.1
Sendmail Sendmail=8.11.2
Sendmail Sendmail=8.11.3
Sendmail Sendmail=8.11.4
Sendmail Sendmail=8.11.5
Sendmail Sendmail=8.11.6
Sendmail Sendmail=8.11.7
Sendmail Sendmail=8.12-beta10
Sendmail Sendmail=8.12-beta12
Sendmail Sendmail=8.12-beta16
Sendmail Sendmail=8.12-beta5
Sendmail Sendmail=8.12-beta7
Sendmail Sendmail=8.12.0
Sendmail Sendmail=8.12.1
Sendmail Sendmail=8.12.2
Sendmail Sendmail=8.12.3
Sendmail Sendmail=8.12.4
Sendmail Sendmail=8.12.5
Sendmail Sendmail=8.12.6
Sendmail Sendmail=8.12.7
Sendmail Sendmail=8.12.8
Sendmail Sendmail=8.12.9
Sendmail Sendmail=8.12.10
Sendmail Sendmail=8.12.11
Event History
Jun 29, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2070?
CVE-2005-2070 is classified as a denial of service vulnerability.
2
How do I fix CVE-2005-2070?
To mitigate CVE-2005-2070, ensure that your ClamAV Mail fILTER is updated to a version beyond 0.85d.
3
Which versions of Sendmail are affected by CVE-2005-2070?
CVE-2005-2070 affects specific versions of Sendmail including 8.8.8, 8.9.1, 8.11.0, 8.12.0, and others.
4
What kind of attack does CVE-2005-2070 facilitate?
CVE-2005-2070 allows remote attackers to keep an open connection, preventing ClamAV from functioning properly.
5
Is this vulnerability exploitable remotely?
Yes, CVE-2005-2070 can be exploited remotely by keeping an open connection to the Sendmail server.