CVE-2006-0058: Race Condition
Published Mar 22, 2006
·Updated
Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.
Affected Software
6 affected components
Sendmail Sendmail=8.13.0
Sendmail Sendmail=8.13.1
Sendmail Sendmail=8.13.2
Sendmail Sendmail=8.13.3
Sendmail Sendmail=8.13.4
Sendmail Sendmail=8.13.5
Remediation
Patch Available
Patch Available
Event History
Mar 22, 2006
CVE Published
08:06 PM
Mar 23, 2006
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0058?
CVE-2006-0058 is classified as critical due to its potential to allow remote code execution.
2
How do I fix CVE-2006-0058?
To mitigate CVE-2006-0058, upgrade Sendmail to version 8.13.6 or later.
3
Which versions of Sendmail are affected by CVE-2006-0058?
CVE-2006-0058 affects Sendmail versions 8.13.0 through 8.13.5.
4
Can CVE-2006-0058 be exploited remotely?
Yes, CVE-2006-0058 can be exploited remotely by triggering timeouts in Sendmail.
5
What impact can CVE-2006-0058 have on my system?
Exploitation of CVE-2006-0058 could lead to arbitrary code execution, compromising system integrity.