CLA-2001:412Vendor advisory
http://distro.conectiva.com.br/atualizacoes?id=a&anuncio=000412 CVE-2001-0653
Sendmail 8.11/8.12 Debugger - Arbitrary Code Execution (1)
Record summary
CVE-2001-0653 has a selected CVSS score of 4.6; EIP currently links 4 catalogued exploits.
Description
Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privileges via a large value in the 'category' part of debugger (-d) command line arguments, which is interpreted as a negative number.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 4
Proofs of concept
4Catalogued exploits
ExploitDBSendmail 8.11/8.12 Debugger - Arbitrary Code Execution (1)ExploitDB exploitby grangeNot analyzed1 file
ExploitDBSendmail 8.11/8.12 Debugger - Arbitrary Code Execution (2)ExploitDB exploitby sd@sf.czNot analyzed1 file
ExploitDBSendmail 8.11/8.12 Debugger - Arbitrary Code Execution (3)ExploitDB exploitby Lucian HudinNot analyzed1 file
ExploitDBSendmail 8.11/8.12 Debugger - Arbitrary Code Execution (4)ExploitDB exploitby RoMaN SoFtNot analyzed1 file
References
Showing 12 of 13IMNX-2001-70-032-01Vendor advisory
http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-032-01 20010821 *ALERT* UPDATED BID 3163 (URGENCY 6.58): Sendmail Debugger Arbitrary Code Execution Vulnerability (fwd)mailing list
http://marc.info/?l=bugtraq&m=99841063100516&w=2 RHSA-2001:106Vendor advisory
http://rhn.redhat.com/errata/RHSA-2001-106.html CSSA-2001-032.0Vendor advisory
http://www.calderasystems.com/support/security/advisories/CSSA-2001-032.0.txt L-133Third-party advisoryGovernment resource
http://www.ciac.org/ciac/bulletins/l-133.shtml MDKSA-2001:075Vendor advisory
http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-075.php3 SuSE-SA:2001:028Vendor advisory
http://www.novell.com/linux/security/advisories/2001_028_sendmail_txt.html 3163vdb entry
http://www.securityfocus.com/bid/3163 sendmail.orgConfirmation
http://www.sendmail.org/8.11.html HPSBTL0112-007Vendor advisory
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0112-007 sendmail-debug-signed-int-overflow(7016)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/7016