Description
mail.local in Sendmail 8.10.x does not properly identify the .\n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 2047 characters long and ends in .\n.
Affected products
- eric_allman / sendmail5.58 – 5.58
- eric_allman / sendmail5.59 – 5.59
- eric_allman / sendmail8.6.x – 8.6.x
- eric_allman / sendmail8.7.1 – 8.7.1
- eric_allman / sendmail8.7.2 – 8.7.2
- eric_allman / sendmail8.7.3 – 8.7.3
- eric_allman / sendmail8.7.4 – 8.7.4
- eric_allman / sendmail8.7.5 – 8.7.5
- eric_allman / sendmail8.7.6 – 8.7.6
- eric_allman / sendmail8.7.x – 8.7.x
- eric_allman / sendmail8.8 – 8.8
- eric_allman / sendmail8.8.1 – 8.8.1
- eric_allman / sendmail8.8.2 – 8.8.2
- eric_allman / sendmail8.8.3 – 8.8.3
- eric_allman / sendmail8.8.4 – 8.8.4
- eric_allman / sendmail8.8.5 – 8.8.5
- eric_allman / sendmail8.8.x – 8.8.x
- eric_allman / sendmail8.9.1 – 8.9.1
- eric_allman / sendmail8.9.3 – 8.9.3