Overview
Older versions of sendmail (circa 1995) incorrectly used popen to process certain arguments.
Description
There is a problem with the way that the older (circa 1995) versions of Sun Microsystems, Inc. version of sendmail processes the -oR option. This problem has been verified as existing in the version of sendmail that is in SunOS 4.1.X, including patches 100377-19 (for SunOS 4.1.3), 101665-04 (for SunOS 4.1.3_U1), and 102423-01 (for SunOS 4.1.4). The -oR option specifies the host, called the mail hub, to which mail should be forwarded when a user on a client of that hub receives mail. This host can be identified with the -oR option on the command line as |
Impact
Local users can obtain root access. |
Solution
Upgrade to the most recent version of sendmail. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to 8lgm for reporting this vulnerability.
This document was written by Larry Rogers and Shawn Hernan. .
Other Information
CVE IDs: | None |
CERT Advisory: | CA-1995-11 |
Severity Metric: | 0.84 |
Date Public: | 1995-08-24 |
Date First Published: | 2003-06-04 |
Date Last Updated: | 2003-06-04 18:44 UTC |
Document Revision: | 4 |