First published: Fri Oct 12 2001(Updated: )
Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to cause a denial of service (data loss) by (1) setting a high initial message hop count option (-h), which causes Sendmail to drop queue entries, (2) via the -qR option, or (3) via the -qS option.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sendmail Sendmail | <=8.12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0714 is considered a high severity vulnerability due to its potential for local denial of service and data loss.
To fix CVE-2001-0714, enable the RestrictQueueRun option in Sendmail configuration.
Sendmail versions before 8.12.1 are affected by CVE-2001-0714.
Attack vectors for CVE-2001-0714 include setting a high message hop count or using specific Sendmail queue options.
Yes, CVE-2001-0714 can lead to data loss by dropping queue entries under specific conditions.