SecurityLex.Org
  Home My IP SecCon Glossary Vulnerability Tests Sans/FBI Top 20 Top 10 Ipfilter Recent Vulnerabilities Today's news Web Host Check 

VulnTests
SecureScout Testcase
eEye Retina RTH
Nessus Plugin ID
nCircle Sans CVE's
Dragonsoft Vuln ID
CVE Entries
Search CVSS vectors 
CVSS Base score between    and
Access Vector Confidentiality Impact
Access Complexity Integrity Impact
Authentification Availability Impact
Impact Bias

Your search for "CVE-2006-0058" returned:
CVE Entries: CVE-2006-0058Name: CVE-2006-0058
CVE References: cve.mitre.org, nvd.nist.gov
SANS/FBI TOP20 Reference:
Risk: HighCVSS Base Score: 7.6 (ver.2.0 upgrade from v1.0)
Access Vector: NetworkAccess Complexity: HighAuthentication: Not required
Confidentiality Impact: CompleteIntegrity Impact: CompleteAvailability Impact: CompleteImpact Bias: N/A
Security vendors coverage:

SecureScout Testcase: 16171 

Nessus Plugin ID: 22557  21190  21191  21381  21128  21132  21135  21134  21121  21893  13592  13541  13454  13350  21260 

Dragonsoft Vuln ID: 2450 
Description: Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.
Vulnerability Type: Race condition
Vulnerable Versions:

Product: sendmail Vendor: sendmail

Versions:
8.13.0
8.13.1
8.13.2
8.13.3
8.13.4
8.13.5
References:

CERT: http://www.us-cert.gov/cas/techalerts/TA06-081A.html

CERT-VN: http://www.kb.cert.org/vuls/id/834865

REDHAT: http://www.redhat.com/support/errata/RHSA-2006-0265.html

REDHAT: http://www.redhat.com/support/errata/RHSA-2006-0264.html

VUPEN: http://www.frsirt.com/english/advisories/2006/1051

VUPEN: http://www.frsirt.com/english/advisories/2006/1049

ISS: http://xforce.iss.net/xforce/alerts/id/216

CONFIRM: http://www.sendmail.com/company/advisory/index.shtml

BUGTRAQ: http://www.securityfocus.com/archive/1/428536/100/0/threaded

OPENPKG: http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.007-sendmail.html

GENTOO: http://www.gentoo.org/security/en/glsa/glsa-200603-21.xml

DEBIAN: http://www.debian.org/security/2006/dsa-1015

SUNALERT: http://sunsolve.sun.com/search/document.do?assetkey=1-66-200494-1

SECUNIA: http://secunia.com/advisories/19367

SECUNIA: http://secunia.com/advisories/19363

SECUNIA: http://secunia.com/advisories/19342

OVAL: http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11074

XF: http://xforce.iss.net/xforce/xfdb/24584

CONFIRM: http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=2751

CONFIRM: http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688

BID: http://www.securityfocus.com/bid/17192

FEDORA: http://www.securityfocus.com/archive/1/archive/1/428656/100/0/threaded

FEDORA: http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00018.html

FEDORA: http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00017.html

OSVDB: http://www.osvdb.org/24037

OPENBSD: http://www.openbsd.org/errata38.html#sendmail

SUSE: http://www.novell.com/linux/security/advisories/2006_17_sendmail.html

MANDRIVA: http://www.mandriva.com/security/advisories?name=MDKSA-2006:058

VUPEN: http://www.frsirt.com/english/advisories/2006/2490

VUPEN: http://www.frsirt.com/english/advisories/2006/2189

VUPEN: http://www.frsirt.com/english/advisories/2006/1529

VUPEN: http://www.frsirt.com/english/advisories/2006/1157

VUPEN: http://www.frsirt.com/english/advisories/2006/1139

VUPEN: http://www.frsirt.com/english/advisories/2006/1072

VUPEN: http://www.frsirt.com/english/advisories/2006/1068

CONFIRM: http://www.f-secure.com/security/fsc-2006-2.shtml

CIAC: http://www.ciac.org/ciac/bulletins/q-151.shtml

AIXAPAR: http://www-1.ibm.com/support/search.wss?rs=0&q=IY82994&apar=only

AIXAPAR: http://www-1.ibm.com/support/search.wss?rs=0&q=IY82993&apar=only

AIXAPAR: http://www-1.ibm.com/support/search.wss?rs=0&q=IY82992&apar=only

CONFIRM: http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm

CONFIRM: http://support.avaya.com/elmodocs2/security/ASA-2006-074.htm

SUNALERT: http://sunsolve.sun.com/search/document.do?assetkey=1-26-102324-1

SUNALERT: http://sunsolve.sun.com/search/document.do?assetkey=1-26-102262-1

SLACKWARE: http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.619600

SECTRACK: http://securitytracker.com/id?1015801

SREASON: http://securityreason.com/securityalert/743

SREASON: http://securityreason.com/securityalert/612

SECUNIA: http://secunia.com/advisories/20723

SECUNIA: http://secunia.com/advisories/20243

SECUNIA: http://secunia.com/advisories/19774

SECUNIA: http://secunia.com/advisories/19676

SECUNIA: http://secunia.com/advisories/19533

SECUNIA: http://secunia.com/advisories/19532

SECUNIA: http://secunia.com/advisories/19466

SECUNIA: http://secunia.com/advisories/19450

SECUNIA: http://secunia.com/advisories/19407

SECUNIA: http://secunia.com/advisories/19404

SECUNIA: http://secunia.com/advisories/19394

SECUNIA: http://secunia.com/advisories/19368

SECUNIA: http://secunia.com/advisories/19361

SECUNIA: http://secunia.com/advisories/19360

SECUNIA: http://secunia.com/advisories/19356

SECUNIA: http://secunia.com/advisories/19349

SECUNIA: http://secunia.com/advisories/19346

SECUNIA: http://secunia.com/advisories/19345

HP: http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635

HP: http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00629555

SGI: ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U

SGI: ftp://patches.sgi.com/support/free/security/advisories/20060302-01-P

SCO: ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.24/SCOSA-2006.24.txt

NETBSD: ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-010.txt.asc

FREEBSD: ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:13.sendmail.asc

OVAL: http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1689

Created: 2006-03-22 00:00:00Last Changed: 2010-08-21 00:00:00
 
 The Complete Lexicon to Security