CWE
NVD-CWE-Other
Advisory Published
Updated

CVE-2002-1165

First published: Thu Oct 03 2002(Updated: )

Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows attackers to bypass the intended restrictions of smrsh by inserting additional commands after (1) "||" sequences or (2) "/" characters, which are not properly filtered or verified.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Sendmail Sendmail=8.12.0
Sendmail Sendmail=8.12.1
Sendmail Sendmail=8.12.2
Sendmail Sendmail=8.12.3
Sendmail Sendmail=8.12.4
Sendmail Sendmail=8.12.5
Sendmail Sendmail=8.12.6
NetBSD NetBSD=1.5
NetBSD NetBSD=1.5.1
NetBSD NetBSD=1.5.2
NetBSD NetBSD=1.5.3
NetBSD NetBSD=1.6

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2002-1165?

    CVE-2002-1165 has been classified as a high-severity vulnerability due to the ease of exploitation and potential impact on system integrity.

  • How do I fix CVE-2002-1165?

    To mitigate CVE-2002-1165, upgrade Sendmail to a version that is not affected by this vulnerability, specifically 8.12.7 or later.

  • What systems are affected by CVE-2002-1165?

    CVE-2002-1165 affects Sendmail versions 8.12.6, 8.11.6-15, and possibly older versions dating back to 5/19/1998.

  • What are the risks associated with CVE-2002-1165?

    Exploitation of CVE-2002-1165 allows attackers to bypass command restrictions, which could lead to unauthorized command execution.

  • Is CVE-2002-1165 still relevant today?

    While CVE-2002-1165 is an older vulnerability, systems running affected versions of Sendmail remain at risk if not properly updated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203