CVE-2001-0653: Medium severity Sendmail Sendmail vulnerability
Published Sep 20, 2001
·Updated
Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privileges via a large value in the 'category' part of debugger (-d) command line arguments, which is interpreted as a negative number.
Affected Software
11 affected components
Sendmail Sendmail=8.11.0
Sendmail Sendmail=8.11.1
Sendmail Sendmail=8.11.2
Sendmail Sendmail=8.11.3
Sendmail Sendmail=8.11.4
Sendmail Sendmail=8.11.5
Sendmail Sendmail=8.12-beta10
Sendmail Sendmail=8.12-beta12
Sendmail Sendmail=8.12-beta16
Sendmail Sendmail=8.12-beta5
Sendmail Sendmail=8.12-beta7
Remediation
Patch Available
Event History
Sep 20, 2001
CVE Published
04:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0653?
CVE-2001-0653 is considered a critical vulnerability due to the potential for privilege escalation.
2
How do I fix CVE-2001-0653?
To fix CVE-2001-0653, upgrade to a version of Sendmail that is not affected, specifically versions after 8.11.5.
3
Who is affected by CVE-2001-0653?
CVE-2001-0653 affects local users of Sendmail versions 8.10.0 through 8.11.5 and 8.12.0 beta.
4
What type of vulnerability is CVE-2001-0653?
CVE-2001-0653 is a privilege escalation vulnerability.
5
Can CVE-2001-0653 be exploited remotely?
No, CVE-2001-0653 can only be exploited by local users.