Junglewise Threat Intelligence

CVE-1999-0129: Sendmail local privilege escalation via .forward or :include: files

CVE-1999-0129 · Severity: medium · CVSS 4.6 · Published 1996-12-03

Technologies: Sendmail. Vendors: Sun Microsystems.

Executive brief

A vulnerability in the Sendmail email routing software allows local users to gain unauthorized file access. By manipulating specific mail forwarding and inclusion files, a user can write to files they should not have access to and gain elevated group permissions. This could lead to the compromise of sensitive data or system configuration files on the affected server.

Technical details

A vulnerability exists in Sendmail (specifically versions prior to 8.8.4) where the handling of .forward and :include: files does not properly restrict file system operations. A local attacker with a system account can exploit this by creating or modifying these files to point to arbitrary locations, allowing them to write to files with the permissions of the group Sendmail is running under. This is a local privilege escalation and file integrity issue. The vulnerability was addressed in Sendmail 8.8.4 and via vendor-specific patches for operating systems like Solaris.

Affected products

  • Sendmail Sendmail 8.8.3 and earlier
  • Sun Microsystems Solaris 2.3, 2.4, 2.5, 2.5.1

Timeline

  • 1996-12-03: disclosed
  • 1996-12-03: advisory: CERT Advisory CA-1996-25 released

References