SMTP_wiz

 

Code: p171

Severity: Critical

 

Description: WIZ command of SMTP can visite Host in a specific environment. The command does not exist in current version, however, the attacker can get root privileges through the command in the previous version.

Impact: UNIX system which supports the old version of Sendmail.

Corrective: Check Sendmail version. If there is the vulnerability, please upgrade version. See http://www.sendmail.org/.