Vulnerability of Sendmail: denial of service via MIME

Synthesis of the vulnerability 

An attacker can use long MIME lines in order to generate an error in Sendmail.
Impacted systems: Sendmail.
Severity of this alert: 2/4.
Creation date: 02/11/2007.
VIGILANCE-VUL-7301

Description of the vulnerability 

The MaxMimeHeaderLength directive, introduced in Sendmail version 8.10.0, defines maximal size of MIME headers:

When this directive is enabled (case by default), the mime8to7() function of sendmail/mime.c file does not correctly handle lines whose size reaches MAXLINE-1 characters. An error thus occurs. This error can stop the daemon.

An attacker can therefore send a malicious email in order to create a denial of service on Sendmail.
Solutions for this threat 

Sendmail: version 8.14.2.
Version 8.14.2 is corrected:
Sendmail: workaround for MIME.
A workaround is to define MaxMimeHeaderLength to 0/0:
  O MaxMimeHeaderLength=0/0
