mail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message even when it is not in interactive mode, which could allow local users to gain root privileges via calls to mail in cron.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openbsd | Openbsd | 2.9 | 2.9 |
Openbsd | Openbsd | 3.0 | 3.0 |