CVE
- Id
- 163
- CVE No.
- CVE-1999-0163
- Status
- Candidate
- Description
- In older versions of Sendmail, an attacker could use a pipe character to execute root commands.
- Phase
- Proposed (19990714)
- Votes
- ACCEPT(2) Frech, Northcutt | MODIFY(1) Prosser | NOOP(2) Baker, Christey | RECAST(1) Shostack
- Comments
- Shostack> there was a "To: |" and a "From: |" attack, which I | think are seperate. | Prosser> older vulnerability, but one additional reference is- | The Ultimate Sendmail Hole List by Markus H・ner @ | bau2.uibk.ac.at/matic/buglist.htm | "|PROGRAM " | Christey> Description needs to be more specific to distinguish between | this and CVE-1999-0203, as alluded to by Adam Shostack