CVE-2006-7175: High severity redhat Enterprise Linux vulnerability
Published Mar 27, 2007
·Updated
The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryption, which could cause less secure channels to be used than desired.
Affected Software
2 affected components
redhat Enterprise Linux=4.0-update4
Sendmail Sendmail=8.13.1.2
Event History
Mar 27, 2007
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
11:19 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-7175?
CVE-2006-7175 is considered a moderate severity vulnerability due to the potential use of insecure SSLv2 encryption.
2
How do I fix CVE-2006-7175?
To fix CVE-2006-7175, update to a later version of Sendmail that allows disabling SSLv2 encryption.
3
Which versions of Sendmail are affected by CVE-2006-7175?
CVE-2006-7175 affects Sendmail version 8.13.1-2 and earlier.
4
Is my system vulnerable if I am using Red Hat Enterprise Linux 4 Update 4?
Yes, if you are using Red Hat Enterprise Linux 4 Update 4 with the affected version of Sendmail, your system is vulnerable.
5
Can I mitigate the risks of CVE-2006-7175 without updating?
Mitigation options are limited, but you can restrict access to the Sendmail service as a temporary measure.