Vulnerability Description
Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.
CVSS Score
7.2
HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sendmail | Sendmail | <= 8.6.7 |
References
- http://www.cert.org/advisories/CA-94.12.sendmail.vulnerabilitiesPatchThird Party AdvisoryUS Government Resource
- http://www.dataguard.no/bugtraq/1994_1/0040.htmlVendor Advisory
- http://www.dataguard.no/bugtraq/1994_1/0042.htmlVendor Advisory
- http://www.dataguard.no/bugtraq/1994_1/0043.html
- http://www.dataguard.no/bugtraq/1994_1/0048.htmlVendor Advisory
- http://www.dataguard.no/bugtraq/1994_1/0078.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7155
- http://www.cert.org/advisories/CA-94.12.sendmail.vulnerabilitiesPatchThird Party AdvisoryUS Government Resource
- http://www.dataguard.no/bugtraq/1994_1/0040.htmlVendor Advisory
- http://www.dataguard.no/bugtraq/1994_1/0042.htmlVendor Advisory
- http://www.dataguard.no/bugtraq/1994_1/0043.html
- http://www.dataguard.no/bugtraq/1994_1/0048.htmlVendor Advisory
- http://www.dataguard.no/bugtraq/1994_1/0078.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7155
FAQ
What is CVE-1999-1309?
CVE-1999-1309 is a vulnerability with a CVSS score of 7.2 (HIGH). Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.
How severe is CVE-1999-1309?
CVE-1999-1309 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-1999-1309?
Check the references section above for vendor advisories and patch information. Affected products include: Sendmail Sendmail.