Vulnerabilities > CVE-2003-1076 - Unspecified vulnerability in SUN Solaris and Sunos
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN sun
nessus
Summary
Unknown vulnerability in sendmail for Solaris 7, 8, and 9 allows local users to cause a denial of service (unknown impact) and possibly gain privileges via certain constructs in a .forward file.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 6 |
Nessus
NASL family | SMTP problems |
NASL id | SENDMAIL_SUN_FORWARD.NASL |
description | The remote sendmail server, according to its version number, may be vulnerable to a local privilege escalation attack when using forward files. *** Sun did not increase the version number of their sendmail *** when patching Solaris 7 and 8, so this might be a false *** positive on these platforms. An attacker may set up a special .forward file in his home and send a mail to himself, which will trick sendmail and will allow him to execute arbitrary commands with root privileges. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11364 |
published | 2003-03-12 |
reporter | This script is Copyright (C) 2003-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/11364 |
title | Solaris sendmail .forward Local Privilege Escalation |
code |
|
References
- http://secunia.com/advisories/8235/
- http://secunia.com/advisories/8235/
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-50904-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-50904-1
- http://www.ciac.org/ciac/bulletins/n-050.shtml
- http://www.ciac.org/ciac/bulletins/n-050.shtml
- http://www.securityfocus.com/bid/7033
- http://www.securityfocus.com/bid/7033
- http://www.securitytracker.com/id?1006234
- http://www.securitytracker.com/id?1006234
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11496
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11496