Junglewise Threat Intelligence

CVE-1999-0145: Sendmail WIZ command enabled allowing root access

CVE-1999-0145 · Severity: high · CVSS 7.2 · Published 1993-09-30

Technologies: Eric Allman Sendmail. Vendors: Eric Allman.

Executive brief

Sendmail is a widely used mail transfer agent for routing and delivering email. A legacy debugging command called 'WIZ' was left enabled in certain versions, which allows anyone with network access to the mail server to gain full administrative (root) control. This could lead to total system takeover, data theft, and the disruption of email services.

Technical details

The vulnerability stems from the 'WIZ' (Wizard) command being enabled in the Sendmail SMTP daemon. This command was originally intended for debugging but lacks proper authentication or restriction in affected versions. By issuing the WIZ command followed by a specific password (often 'shell' or similar known strings in older versions), an attacker can spawn a root shell. This is a classic example of a 'backdoor' or 'debug' command left in production code. While the CVSS 2.0 vector provided by NVD suggests local access (AV:L), historical context and the nature of SMTP indicate this was frequently exploited over the network.

Affected products

  • Sendmail Sendmail Versions prior to 1993 patches

Timeline

  • 1993-09-30: advisory: NVD published date
  • 1990-11-01: other: Related CERT advisory CA-1990-11 issued

References

Related threats