Vulnerability Name:

CVE-1999-1580 (CCN-20885)

Assigned:1995-08-23
Published:1995-08-23
Updated:2008-09-05
Summary:SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable and passing crafted values to the -oR option.
CVSS v3 Severity:9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-1999-1580

Source: MISC
Type: Exploit
http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-21.html

Source: AUSCERT
Type: Vendor Advisory
AA-95.09

Source: CCN
Type: CERT(sm) Advisory CA-95:11
Sun Sendmail -oR Vulnerability

Source: CERT
Type: Patch, Third Party Advisory, US Government Resource
CA-1995-11

Source: CCN
Type: US-CERT VU#3278
SunOS versions of sendmail use popen to return undeliverable mail

Source: CERT-VN
Type: Third Party Advisory, US Government Resource
VU#3278

Source: CCN
Type: OSVDB ID: 14880
SunOS Sendmail -oR Option IFS Variable Privilege Escalation

Source: BID
Type: UNKNOWN
7829

Source: CCN
Type: BID-7829
Sendmail V.5 -oR Privilege Escalation Vulnerability

Source: CCN
Type: Sendmail Web site
Sendmail 8.12.10

Source: XF
Type: UNKNOWN
sunos-sendmail-ifs-gain-privilege(20885)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:sendmail:sendmail:5.59:*:*:*:*:*:*:*
  • OR cpe:/a:sendmail:sendmail:5.61:*:*:*:*:*:*:*
  • OR cpe:/a:sendmail:sendmail:5.65:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:sun:sunos:4.1.1:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:4.1.2:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:4.1.3:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:4.1.3c:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:4.1.3u1:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:4.1.4:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:4.1.4jl:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:sendmail:sendmail:5.59:*:*:*:*:*:*:*
  • OR cpe:/a:sendmail:sendmail:5.61:*:*:*:*:*:*:*
  • OR cpe:/a:sendmail:sendmail:5.65:*:*:*:*:*:*:*
  • AND
  • cpe:/o:sun:sunos:4.1.1:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:4.1.3:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:4.1.4:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:4.1.2:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:4.1.3c:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:4.1.4jl:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:4.1.3u1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sendmail sendmail 5.59
    sendmail sendmail 5.61
    sendmail sendmail 5.65
    sun sunos 4.1.1
    sun sunos 4.1.2
    sun sunos 4.1.3
    sun sunos 4.1.3c
    sun sunos 4.1.3u1
    sun sunos 4.1.4
    sun sunos 4.1.4jl
    sendmail sendmail 5.59
    sendmail sendmail 5.61
    sendmail sendmail 5.65
    sun sunos 4.1.1
    sun sunos 4.1.3
    sun sunos 4.1.4
    sun sunos 4.1.2
    sun sunos 4.1.3c
    sun sunos 4.1.4jl
    sun sunos 4.1.3u1