CNCVE编号:CNCVE-20010713 CVE编号:CAN-2001-0713 安全级别:中 漏洞中文描述: 当使用-C选项装入自定义配置文件时,Sendmail 8.12.1早期版本不能正确地撤消权限,这允许本地用户通过文件名包含带有高字节设置的字符的配置文件中的畸形参数来获得权限,这些高字节设置如下:(1)一个字符长的宏名;(2)被setoption 函数处理的变量设置或(3)被getmodifiers处理的Modifiers设置。 漏洞英文描述: Sendmail before 8.12.1 does not properly drop privileges when the -C option is used to load custom configuration files, which allows local users to gain privileges via malformed arguments in the configuration file whose names contain characters with the h 漏洞参考: Reference: BINDVIEW:20011001 Multiple Local Sendmail Vulnerabilities Reference: URL:http://razor.bindview.com/portal/resource/publish/advisories/adv_sm812.html 系统类型:其他 漏洞类型:设计错误