Executive brief
Sendmail, a widely used mail transfer agent for routing and delivering email, contains a vulnerability that allows a local user to take full control of the system. By providing a specially crafted large value to the program's debugging feature, an attacker can bypass security restrictions and gain administrative (root) privileges. This could lead to a complete compromise of the server, including the ability to access any data or disrupt email services.
Technical details
A vulnerability exists in Sendmail versions prior to 8.6.7 due to improper handling of the debug (-d) command line option. A local attacker can provide an excessively large value to this parameter, leading to a memory corruption or buffer overflow condition. Because Sendmail often runs with elevated privileges (setuid root) to manage mail delivery, this flaw allows a non-privileged local user to execute arbitrary code with root privileges. The issue is resolved in Sendmail version 8.6.7.
Affected products
- Sendmail Sendmail before 8.6.7
Timeline
- 1994-01-01: disclosed: Vulnerability discussed in Bugtraq and CERT advisories in 1994
- 1996-08-30: advisory: NVD publication date
References
- http://www.cert.org/advisories/CA-94.12.sendmail.vulnerabilities
- http://www.dataguard.no/bugtraq/1994_1/0040.html
- http://www.dataguard.no/bugtraq/1994_1/0042.html
- http://www.dataguard.no/bugtraq/1994_1/0043.html
- http://www.dataguard.no/bugtraq/1994_1/0048.html
- http://www.dataguard.no/bugtraq/1994_1/0078.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7155