CVE-2009-1490
Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.
- Affected products
- Sendmail
- Sendmail
- ≤ 8.13.1.2, 2.6, 2.6.1, 2.6.2, 3.0, 3.0.1, 3.0.2, 3.0.3, 4.1, 4.55, 5, 5.59, 5.61, 5.65, 8.6.7, 8.7.6, 8.7.7, 8.7.8, 8.7.9, 8.7.10, 8.8.8, 8.9.0, 8.9.1, 8.9.2, 8.9.3, 8.10, 8.10.0, 8.10.1, 8.10.2, 8.11.0, 8.11.1, 8.11.2, 8.11.3, 8.11.4, 8.11.5, 8.11.6, 8.11.7, 8.12, 8.12.0, 8.12.1
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 12.6% (96th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2009-05-05
CVE-2009-1490 at NVD
2 known exploits for CVE-2009-1490
Proof-of-concept code and exploit modules indexed by Sploitus