SMTP_Pipe

 

Code: p175

Severity: Critical

 

Description: Insert "|" symbol to some item of the e-mail, Sendmail can execute commands. The result is that attacker executes these commands with root privileges.

Impact: UNIX system which supports the old version of Sendmail.

Corrective: Check Sendmail version. If there is the vulnerability, please upgrade version. See http://www.sendmail.org/.