Vixie Cron MAILTO Sendmail Vulnerability
BID:611
Info
Vixie Cron MAILTO Sendmail Vulnerability
| Bugtraq ID: | 611 |
| Class: | Input Validation Error |
| CVE: |
CVE-1999-0769 CVE-1999-0872 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 25 1999 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | The vulnerability was announced by RedHat Software. The exploit is from Olaf Kirch. |
| Vulnerable: |
Redhat Linux 6.0 Redhat Linux 5.2 i386 Redhat Linux 5.1 Redhat Linux 5.0 Redhat Linux 4.2 Redhat Linux 4.1 Redhat Linux 4.0 Paul Vixie Vixie Cron 3.0 pl1 Debian Linux 2.2 Debian Linux 2.1 Caldera OpenLinux 2.2 |
| Not Vulnerable: |
Slackware Linux 4.0 |
Discussion
Vixie Cron MAILTO Sendmail Vulnerability
Failure by the vixie cron daemon from validating the contents of a user supplied environment variable allow a malicious users to pass arbitrary command line arguments to sendmail while running as the root user.
The cron daemon uses the cron_popen function to send email to the user that queue commands for execution by cron. The user can set a MAILTO environment variable before calling cron to have it send the email to a different address. The cron daemon passes the contents of this environment variable to sendmail via the command line while executing as the root user. This allow a local malicious user to obtain root access.
Failure by the vixie cron daemon from validating the contents of a user supplied environment variable allow a malicious users to pass arbitrary command line arguments to sendmail while running as the root user.
The cron daemon uses the cron_popen function to send email to the user that queue commands for execution by cron. The user can set a MAILTO environment variable before calling cron to have it send the email to a different address. The cron daemon passes the contents of this environment variable to sendmail via the command line while executing as the root user. This allow a local malicious user to obtain root access.
References
Vixie Cron MAILTO Sendmail Vulnerability
References:
References: