First published: Thu Aug 17 1995(Updated: )
In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a program.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sendmail | =8.6.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0203 is considered a high severity vulnerability due to the potential for attackers to gain root privileges.
To fix CVE-1999-0203, upgrade Sendmail to version 8.6.11 or later, which addresses the vulnerability.
CVE-1999-0203 is an improper input validation vulnerability in Sendmail that allows privilege escalation.
The affected version is Sendmail 8.6.10; earlier and some subsequent versions may also be impacted if not patched.
Exploiting CVE-1999-0203 can allow an attacker to execute arbitrary commands with root privileges, compromising system security.