Vulnerabilities > CVE-1999-0203 - Unspecified vulnerability in Eric Allman Sendmail 8.6.10
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN eric-allman
nessus
Summary
In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a program.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | SMTP problems |
NASL id | SMTP_BOUNCE.NASL |
description | The remote SMTP server did not complain when issued the command : MAIL FROM: |testing This probably means that it is possible to send mail that will be bounced to a program, which is a serious threat, since this allows anyone to execute arbitrary commands on this host. *** This security hole might be a false positive, since *** some MTAs will not complain to this test, but instead *** just drop the message silently |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 10258 |
published | 1999-08-22 |
reporter | This script is Copyright (C) 1999-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/10258 |
title | Sendmail MAIL FROM Command Arbitrary Remote Command Execution |
code |
|