SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable and passing crafted values to the -oR option.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sendmail | Sendmail | 5.59 | 5.59 |
Sendmail | Sendmail | 5.61 | 5.61 |
Sendmail | Sendmail | 5.65 | 5.65 |