CVE Vulnerabilities

CVE-2002-1165

Published: Oct 11, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Sendmail Consortiums Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows attackers to bypass the intended restrictions of smrsh by inserting additional commands after (1) || sequences or (2) / characters, which are not properly filtered or verified.

Affected Software

NameVendorStart VersionEnd Version
SendmailSendmail8.12.0 (including)8.12.0 (including)
SendmailSendmail8.12.1 (including)8.12.1 (including)
SendmailSendmail8.12.2 (including)8.12.2 (including)
SendmailSendmail8.12.3 (including)8.12.3 (including)
SendmailSendmail8.12.4 (including)8.12.4 (including)
SendmailSendmail8.12.5 (including)8.12.5 (including)
SendmailSendmail8.12.6 (including)8.12.6 (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Linux 6.2RedHat*
Red Hat Linux 7.0RedHat*
Red Hat Linux 7.1RedHat*
Red Hat Linux 7.1RedHat*
Red Hat Linux 7.2RedHat*
Red Hat Linux 7.3RedHat*
Red Hat Linux 8.0RedHat*
Red Hat Linux Advanced Workstation 2.1RedHat*
SendmailUbuntudapper*
SendmailUbuntudevel*
SendmailUbuntuedgy*
SendmailUbuntufeisty*

References