Security features bypass in Sendmail - #VU67946

 

Security features bypass in Sendmail - #VU67946

Published: October 5, 2022


Vulnerability identifier: #VU67946
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disable TLS encryption.

The vulnerability exists due to an error related to SMTP session reuse. If sendmail tries to reuse an SMTP session which had already been closed by the server, then the connection cache can have invalid information about the session. As a result, STARTTLS is never used for the new session, even if offered by the peer.


Affected software

Sendmail
SUSE Linux Enterprise Module for Legacy Software
sendmail-debugsource
sendmail-debuginfo
sendmail

Remediation

Install updates from vendor's website.

Sendmail - update to 8.16.1
sendmail-debugsource - update to 8.14.9-4.3.1
sendmail-debuginfo - update to 8.14.9-4.3.1
sendmail - update to 8.14.9-4.3.1

External References

Related Security Bulletins