CVE-1999-1580: SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root
Summary
SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable and passing crafted values to the -oR option.
Severity
UNKNOWN
Source Attribution
Source: NVD · Updated: 2026-08-21T04:30:36.682Z · Confidence: high
Impact
Based on CVSS vector: n/a — assess confidentiality, integrity, and availability impact via the official vector documentation.
Affected Software
Fix
Upgrade affected software to the fixed version identified above. Apply vendor patches and monitor advisories before exposed systems go unpatched.
References
- http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-21.html
- http://www.auscert.org.au/render.html?it=1853&cid=1978
- http://www.cert.org/advisories/CA-95.11.sun.sendmail-oR.vul
- http://www.kb.cert.org/vuls/id/3278
- http://www.securityfocus.com/bid/7829
- http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-21.html
- http://www.auscert.org.au/render.html?it=1853&cid=1978
- http://www.cert.org/advisories/CA-95.11.sun.sendmail-oR.vul
- http://www.kb.cert.org/vuls/id/3278
- http://www.securityfocus.com/bid/7829