CVE-1999-1309: High severity sendmail sendmail vulnerability
Published Aug 30, 1996
·Updated
Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.
Affected Software
1 affected component
Sendmail Sendmail<=8.6.7
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Sendmailto a version that resolves this vulnerability.Fixed in 8.6.7
Event History
Aug 30, 1996
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-1999-1309?
CVE-1999-1309 has a critical severity level as it allows local users to gain root access.
2
How do I fix CVE-1999-1309?
To fix CVE-1999-1309, upgrade Sendmail to version 8.6.8 or later.
3
What versions of Sendmail are affected by CVE-1999-1309?
CVE-1999-1309 affects all versions of Sendmail prior to 8.6.8, including 8.6.7 and earlier.
4
What type of access does CVE-1999-1309 exploit?
CVE-1999-1309 exploits local user access to gain root privileges through the debug command line option.
5
Is CVE-1999-1309 a zero-day vulnerability?
CVE-1999-1309 is not a zero-day vulnerability as it has been publicly documented and known for many years.