Sendmail Inadequate Privilege Lowering Vulnerability
BID:3377
Info
Sendmail Inadequate Privilege Lowering Vulnerability
| Bugtraq ID: | 3377 |
| Class: | Design Error |
| CVE: |
CVE-2001-0713 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 01 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | Discovered by Michal Zalewski <[email protected]>. |
| Vulnerable: |
Sendmail Consortium Sendmail 8.12 .0 |
| Not Vulnerable: |
Sendmail Consortium Sendmail 8.12.1 |
Discussion
Sendmail Inadequate Privilege Lowering Vulnerability
Sendmail is a widely used MTA often shipped with Unix systems.
In version 8.12.0, the 'sendmail' utility is setgid instead of setuid. The code that drops privileges does not lower the saved groupid. It is therefore possible to reclaim the effective groupid if an attacker can force the process to call setregid(). This may be possible due to several bugs in the config file parser.
Sendmail is a widely used MTA often shipped with Unix systems.
In version 8.12.0, the 'sendmail' utility is setgid instead of setuid. The code that drops privileges does not lower the saved groupid. It is therefore possible to reclaim the effective groupid if an attacker can force the process to call setregid(). This may be possible due to several bugs in the config file parser.
Exploit / POC
Sendmail Inadequate Privilege Lowering Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Sendmail Inadequate Privilege Lowering Vulnerability
Solution:
This vulnerability is corrected in Sendmail version 8.12.1.
Sendmail Consortium Sendmail 8.12 .0
Solution:
This vulnerability is corrected in Sendmail version 8.12.1.
Sendmail Consortium Sendmail 8.12 .0
-
Sendmail Consortium Sendmail 8.12.1
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.1.tar.Z
References
Sendmail Inadequate Privilege Lowering Vulnerability
References:
References:
- Support Web page for Free Sendmail (Sendmail Consortium)
- Web Page for the Commercially Supported Sendmail (Sendmail Consortium)