CVE-2002-0906
EPSS 4.4%
Description
Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malicious DNS server.
How to fix CVE-2002-0906
To remediate CVE-2002-0906, upgrade the affected package to a fixed version below.
- Debian/sendmail—upgrade to 8.12.5 or later
Is CVE-2002-0906 being exploited?
Low — EPSS is 4.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 8.12.5