The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.
| Software | From | Fixed in |
|---|---|---|
| redhat / sendmail | 8.12.8-4 | 8.12.8-4.x |
| redhat / sendmail | 8.12.5-7 | 8.12.5-7.x |
| sendmail / sendmail | 8.12.3 | 8.12.3.x |
| sendmail / sendmail | 8.12.8 | 8.12.8.x |
| sgi / irix | 6.5.21 | 6.5.21.x |
| sgi / irix | 6.5.19 | 6.5.19.x |
| sendmail / sendmail | 8.12.4 | 8.12.4.x |
| sgi / irix | 6.5.20 | 6.5.20.x |
| sendmail / sendmail | 8.12.1 | 8.12.1.x |
| sendmail / sendmail | 8.12.5 | 8.12.5.x |
| sendmail / sendmail | 8.12.2 | 8.12.2.x |
| sendmail / sendmail | 8.12.6 | 8.12.6.x |
| sendmail / sendmail | 8.12.7 | 8.12.7.x |
| freebsd / freebsd | 4.7 | 4.7.x |
| compaq / tru64 | 5.0a | 5.0a.x |
| openbsd / openbsd | 3.2 | 3.2.x |
| freebsd / freebsd | 4.8 | 4.8.x |
| freebsd / freebsd | 4.6 | 4.6.x |
| compaq / tru64 | 5.1 | 5.1.x |
| freebsd / freebsd | 5.0 | 5.0.x |