CVE-2001-0714: Low severity Sendmail Sendmail vulnerability
Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to cause a denial of service (data loss) by (1) setting a high initial message hop count option (-h), which causes Sendmail to drop queue entries, (2) via the -qR option, or (3) via the -qS option.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-0714?
CVE-2001-0714 is considered a high severity vulnerability due to its potential for local denial of service and data loss.
How do I fix CVE-2001-0714?
To fix CVE-2001-0714, enable the RestrictQueueRun option in Sendmail configuration.
Which versions of Sendmail are affected by CVE-2001-0714?
Sendmail versions before 8.12.1 are affected by CVE-2001-0714.
What are the attack vectors for CVE-2001-0714?
Attack vectors for CVE-2001-0714 include setting a high message hop count or using specific Sendmail queue options.
Can CVE-2001-0714 lead to data loss?
Yes, CVE-2001-0714 can lead to data loss by dropping queue entries under specific conditions.