Berkeley Sendmail MIME Vulnerability
BID:685
Info
Berkeley Sendmail MIME Vulnerability
| Bugtraq ID: | 685 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jan 20 1997 12:00AM |
| Updated: | Jan 20 1997 12:00AM |
| Credit: | This vulnerability was reported in CERT advisory CA-97.05. |
| Vulnerable: |
Eric Allman Sendmail 8.8.4 Eric Allman Sendmail 8.8.3 Caldera OpenLinux Base 1.0 BSDI BSD/OS 2.1 |
| Not Vulnerable: |
Eric Allman Sendmail 8.8.5 |
Discussion
Berkeley Sendmail MIME Vulnerability
From version 8.8.3 a vulnerability was introduced in the MIME support for sendmail. This description was taken from the CERT advisory CA-97.05:
With the release of sendmail version 8.8.3, a serious security vulnerability was introduced that allows remote users to execute arbitrary commands on the local system with root privileges. By sending a carefully crafted email message to a system running a vulnerable version of sendmail, intruders may be able to force sendmail to execute arbitrary commands with root privileges. Those commands are run on the same system where the vulnerable sendmail is running.
From version 8.8.3 a vulnerability was introduced in the MIME support for sendmail. This description was taken from the CERT advisory CA-97.05:
With the release of sendmail version 8.8.3, a serious security vulnerability was introduced that allows remote users to execute arbitrary commands on the local system with root privileges. By sending a carefully crafted email message to a system running a vulnerable version of sendmail, intruders may be able to force sendmail to execute arbitrary commands with root privileges. Those commands are run on the same system where the vulnerable sendmail is running.
Exploit / POC
Berkeley Sendmail MIME Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Berkeley Sendmail MIME Vulnerability
Solution:
The best solution is to upgrade sendmail to version 8.8.5 or later.
Solution:
The best solution is to upgrade sendmail to version 8.8.5 or later.