Junglewise Threat Intelligence

CVE-1999-0131: Sendmail buffer overflow in GECOS field

CVE-1999-0131 · Severity: high · CVSS 7.2 · Published 1996-09-11

Technologies: Sendmail.

Executive brief

A vulnerability in Sendmail, a widely used mail transfer agent, allows local users to gain full administrative control over the system. By exploiting a flaw in how the software handles user information fields, an attacker can crash the service or execute malicious commands with the highest level of privileges. This could lead to a complete compromise of the server and any data stored on it.

Technical details

A buffer overflow vulnerability exists in Sendmail versions 8.7.5 and earlier within the handling of the GECOS (General Electric Comprehensive Operating System) field in the system password file. The flaw is triggered when Sendmail processes user information that exceeds expected buffer lengths. A local attacker with the ability to modify their own GECOS information or influence how Sendmail parses it can overwrite memory to execute arbitrary code with root privileges. This vulnerability also allows for a denial of service by crashing the mail daemon. Users should upgrade to a version later than 8.7.5 to mitigate this risk.

Affected products

  • Sendmail Sendmail 8.7.5 and earlier

Timeline

  • 1996-09-11: disclosed

References