PT-2001-1896 · Sendmail · Sendmail
Published
2001-10-12
·
Updated
2008-09-05
·
CVE-2001-0713
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Sendmail versions prior to 8.12.1
Description:
The issue allows local users to gain privileges through malformed arguments in custom configuration files loaded with the -C option. This can be achieved with configuration file names containing characters with the high bit set, such as short macro names, variable settings processed by the
setoption function, or Modifiers settings processed by the getmodifiers function.Recommendations:
For Sendmail versions prior to 8.12.1, update to version 8.12.1 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sendmail