[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

254492

 
 

909

 
 

198437

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2001-0653Date: (C)2001-09-20   (M)2023-12-22


Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privileges via a large value in the 'category' part of debugger (-d) command line arguments, which is interpreted as a negative number.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.6
Exploit Score: 3.9
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
http://marc.info/?l=bugtraq&m=99841063100516&w=2
BID-3163
CLA-2001:412
CSSA-2001-032.0
HPSBTL0112-007
IMNX-2001-70-032-01
L-133
MDKSA-2001:075
NetBSD-SA2001-017
RHSA-2001:106
SuSE-SA:2001:028
http://www.sendmail.org/8.11.html
sendmail-debug-signed-int-overflow(7016)

CPE    11
cpe:/a:sendmail:sendmail:8.12:beta7
cpe:/a:sendmail:sendmail:8.12:beta12
cpe:/a:sendmail:sendmail:8.12:beta5
cpe:/a:sendmail:sendmail:8.12:beta10
...

© SecPod Technologies