PT-2010-1031 · Sendmail+2 · Sendmail+2

Published

2010-01-04

·

Updated

2017-09-19

·

CVE-2009-4565

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions sendmail versions prior to 8.14.4
Description The issue allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority. It also allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority. This is related to the handling of a '0' character in a Common Name (CN) field of an X.509 certificate.
Recommendations For sendmail versions prior to 8.14.4, update to version 8.14.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of SSL-based SMTP servers and client certificates until a patch is applied. Avoid using crafted server or client certificates that may exploit this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03060
CVE-2009-4565
DSA-1985-1
HPSBUX02508
RHSA-2010:0237
RHSA-2010_0237
RHSA-2011:0262
RHSA-2011_0262

Affected Products

Hp-Ux
Red Hat
Sendmail