Security features bypass in Sendmail - #VU67946
Published: October 5, 2022
Vulnerability details
The vulnerability allows a remote attacker to disable TLS encryption.
The vulnerability exists due to an error related to SMTP session reuse. If sendmail tries to reuse an SMTP session which had already been closed by the server, then the connection cache can have invalid information about the session. As a result, STARTTLS is never used for the new session, even if offered by the peer.
Affected software
SUSE Linux Enterprise Module for Legacy Software
sendmail-debugsource
sendmail-debuginfo
sendmail
Remediation
sendmail-debugsource - update to 8.14.9-4.3.1
sendmail-debuginfo - update to 8.14.9-4.3.1
sendmail - update to 8.14.9-4.3.1