OSVDB ID: 58100

Title: Sendmail Controlling User Queue File Resource Starvation DoS

Info

Disclosure

Sep 18, 1996

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Sendmail contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when getpwuid fails. This flaw may lead to a loss of availability and privilege escalation.

Classification

Location: Local Access Required
Attack Type: Denial of Service
Impact: Loss of Availability
Solution: Upgrade
Exploit: Exploit Unknown
Disclosure: Vendor Verified

Solution

Upgrade to version 8.7.6, 8.8.x or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Sendmail

Sendmail

8.75

The FreeBSD Project

2.1.5

Hewlett-Packard Development Company, L.P.

HP-UX

9.x
10.x

IBM Corporation

AIX

3.2
4.1
4.2

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/58100