4.6
CVSSv2

CVE-2001-0653

Published: 20/09/2001 Updated: 03/05/2018
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 480
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Sendmail 8.10.0 up to and including 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privileges via a large value in the 'category' part of debugger (-d) command line arguments, which is interpreted as a negative number.

Vulnerable Product Search on Vulmon Subscribe to Product

sendmail sendmail 8.12

sendmail sendmail 8.11.0

sendmail sendmail 8.11.1

sendmail sendmail 8.11.2

sendmail sendmail 8.11.3

sendmail sendmail 8.11.4

sendmail sendmail 8.11.5

Exploits

source: wwwsecurityfocuscom/bid/3163/info An input validation error exists in Sendmail's debugging functionality The problem is the result of the use of signed integers in the program's tTflag() function, which is responsible for processing arguments supplied from the command line with the '-d' switch and writing the values to it's in ...
source: wwwsecurityfocuscom/bid/3163/info An input validation error exists in Sendmail's debugging functionality The problem is the result of the use of signed integers in the program's tTflag() function, which is responsible for processing arguments supplied from the command line with the '-d' switch and writing the values to it' ...
source: wwwsecurityfocuscom/bid/3163/info An input validation error exists in Sendmail's debugging functionality The problem is the result of the use of signed integers in the program's tTflag() function, which is responsible for processing arguments supplied from the command line with the '-d' switch and writing the values to it's inte ...
source: wwwsecurityfocuscom/bid/3163/info An input validation error exists in Sendmail's debugging functionality The problem is the result of the use of signed integers in the program's tTflag() function, which is responsible for processing arguments supplied from the command line with the '-d' switch and writing the values to it's ...