SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable and passing crafted values to the -oR option.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sendmail | Sendmail | 5.59 (including) | 5.59 (including) |
Sendmail | Sendmail | 5.61 (including) | 5.61 (including) |
Sendmail | Sendmail | 5.65 (including) | 5.65 (including) |