Vulnerability Name: | CCN-3594 | ||||||
Published: | 1999-11-24 | ||||||
Updated: | 1999-11-24 | ||||||
Summary: | Sendmail hasa race condition denial of service. Any user with shell access can cause the aliases database to rebuild by sending /usr/sbin/sendmail the -bi parameter. During the small delay between passing the command and when the database rebuilds, the user can send any signal to the database process such SIGKILL and cause the sendmail service to crash. | ||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||
CVSS v2 Severity: | 2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P) 1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||
Vulnerability Consequences: | Denial of Service | ||||||
References: | Source: CCN Type: BugTraq Mailing List, Wed, 24 Nov 1999 02:40:48 -0800 [ COBALT ] Security Advisory - Sendmail Source: CCN Type: Sendmail Consortium Web site Sendmail.org Source: XF Type: UNKNOWN sendmail-dbrebuild-race-dos(3594) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |