Executive brief
A vulnerability in the Sendmail mail server on older SunOS systems allows remote attackers to gain unauthorized access to the 'bin' user account. Sendmail is a critical service responsible for routing and delivering email across a network. Successful exploitation could allow an attacker to manipulate system files or use the compromised account as a stepping stone for further attacks on the organization's infrastructure.
Technical details
A vulnerability exists in the SMI (Sun Microsystems, Inc.) version of Sendmail 4.0 and earlier running on SunOS versions up to 4.0.3. The flaw allows a remote, unauthenticated attacker to gain access to the 'bin' user account via the network. While the specific root cause (e.g., buffer overflow or configuration error) is not detailed in the legacy advisory, the impact is a partial loss of confidentiality, integrity, and availability. Attackers can leverage this access to interact with system binaries and potentially escalate privileges. Patches were historically provided by the vendor to address this issue.
Affected products
- Sun Microsystems SunOS up to 4.0.3
- Sun Microsystems Sendmail (SMI) 4.0 and earlier
Timeline
- 1990-01-29: advisory: Initial advisory published by CERT/CC and NVD