Executive brief
A vulnerability in the Sendmail component of SunOS allows local users to gain full administrative control of the system. Sendmail is a standard service used for routing and delivering electronic mail. By exploiting how the system handles mail forwarding instructions, a person with basic access to the computer can bypass security restrictions to execute commands as the root user, potentially leading to a total system compromise.
Technical details
SunOS Sendmail (versions 5.59 through 5.65) is vulnerable to a privilege escalation attack due to the insecure use of the popen() function when processing the forwarding host argument. A local attacker can exploit this by modifying the Internal Field Separator (IFS) environment variable and passing crafted values to the -oR command-line option (or via equivalent configuration in the OR macro). Because popen() invokes a shell to execute commands, the manipulated IFS variable allows the attacker to redirect the execution flow and run arbitrary commands with root privileges. This issue affects SunOS 4.1.x and was originally addressed in 1995 via patches such as 100377-19, 101665-04, and 102423-01.
Affected products
- Sun Microsystems SunOS 4.1.x, 5.59 through 5.65
Timeline
- 1995-08-23: disclosed: Initial public disclosure of the vulnerability.
- 1995-08-23: advisory: CERT Advisory CA-95.11 released.
- 1995-08-23: patched: Patches released by Sun Microsystems.