CVE-1999-0145: High severity Eric Allman Sendmail vulnerability
Published Sep 30, 1993
·Updated
Sendmail WIZ command enabled, allowing root access.
Affected Software
2 affected componentsFixes available
Eric Allman Sendmail
Microsoft cbl2 sendmail 8.15.2-46
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the WIZ command in the Sendmail configuration to prevent unauthorized root access.
Sendmail WIZ command = disabled
Event History
Sep 30, 1993
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Oct 13, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Oct 1, 2025
Data Sourced
via Microsoft·11:10 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·11:10 PM
Affected Software
Updated
via Microsoft·11:10 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-1999-0145?
CVE-1999-0145 has a high severity level due to its potential to allow unauthorized root access to a system.
2
How do I fix CVE-1999-0145?
To fix CVE-1999-0145, disable the WIZ command in Sendmail and upgrade to a patched version.
3
What versions of Sendmail are affected by CVE-1999-0145?
CVE-1999-0145 affects all versions of Sendmail prior to the inclusion of the fix for this vulnerability.
4
Can CVE-1999-0145 be exploited remotely?
Yes, CVE-1999-0145 can be exploited remotely by attackers to gain root access to vulnerable systems.
5
Is it safe to run Sendmail if CVE-1999-0145 is present?
It is not safe to run Sendmail with CVE-1999-0145 present, as it poses a significant security risk.