PT-2001-1896 · Sendmail · Sendmail

Published

2001-10-12

·

Updated

2008-09-05

·

CVE-2001-0713

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Sendmail versions prior to 8.12.1
Description: The issue allows local users to gain privileges through malformed arguments in custom configuration files loaded with the -C option. This can be achieved with configuration file names containing characters with the high bit set, such as short macro names, variable settings processed by the setoption function, or Modifiers settings processed by the getmodifiers function.
Recommendations: For Sendmail versions prior to 8.12.1, update to version 8.12.1 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0713

Affected Products

Sendmail