Sendmail Aliases Database Regeneration Vulnerability
BID:857
Info
Sendmail Aliases Database Regeneration Vulnerability
| Bugtraq ID: | 857 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 07 1999 12:00AM |
| Updated: | Dec 07 1999 12:00AM |
| Credit: | First exposed in a Debian GNU/Linux advisory published on Dec 7, 1999. |
| Vulnerable: |
Eric Allman Sendmail 8.9.3 |
| Not Vulnerable: |
Eric Allman Sendmail 8.9.3 -3slink1 |
Discussion
Sendmail Aliases Database Regeneration Vulnerability
To regenerate the sendmail aliases database, sendmail is run locally with the -bi parameters. No checks are made against the users priviliges to determine whether they are able to do this or not. Consequently, it is possible for a malicious user to attempt to regenerate the aliases database and then interrupt it, corrupting the database.
To regenerate the sendmail aliases database, sendmail is run locally with the -bi parameters. No checks are made against the users priviliges to determine whether they are able to do this or not. Consequently, it is possible for a malicious user to attempt to regenerate the aliases database and then interrupt it, corrupting the database.