Vulnerabilities > CVE-1999-0163 - Unspecified vulnerability in Eric Allman Sendmail

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
eric-allman
nessus

Summary

In older versions of Sendmail, an attacker could use a pipe character to execute root commands.

Vulnerable Configurations

Part Description Count
Application
Eric_Allman
1

Nessus

NASL familySMTP problems
NASL idSMTP_PROGRAM.NASL
descriptionThe remote SMTP server did not complain when issued the command : MAIL FROM: root@this_host RCPT TO: |testing This probably means that it is possible to send mail directly to programs, which is a serious threat, since this allows anyone to execute arbitrary commands on this host. *** This security hole might be a false positive, since *** some MTAs will not complain to this test, but instead *** just drop the message silently.
last seen2020-06-01
modified2020-06-02
plugin id10261
published1999-08-22
reporterThis script is Copyright (C) 1999-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/10261
titleSendmail mail from/rcpt to Pipe Arbitrary Command Execution