CVE-2001-0713
Last modified
CVE-2001-0713 is a vulnerability of currently unknown severity. Sendmail before 8.12.1 does not properly drop privileges when the -C option is used to load custom configuration files, which allows local users to gain privileges via malformed arguments in the configuration file whose names contain characters with the high bit set, such as (1) macro names that are one character long, (2) a variable setting which is processed by the setoption function, or (3) a Modifiers setting which is processed by the getmodifiers function.. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
Sendmail before 8.12.1 does not properly drop privileges when the -C option is used to load custom configuration files, which allows local users to gain privileges via malformed arguments in the configuration file whose names contain characters with the high bit set, such as (1) macro names that are one character long, (2) a variable setting which is processed by the setoption function, or (3) a Modifiers setting which is processed by the getmodifiers function.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sendmail | Sendmail | <= 8.12.1 |
References
- http://razor.bindview.com/publish/advisories/adv_sm812.htmlVendor Advisory
- http://razor.bindview.com/publish/advisories/adv_sm812.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-0713?
How severe is CVE-2001-0713?
How do I fix CVE-2001-0713?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2001
- CVE-2001-0707Denicomp RSHD 2.18 and earlier allows a remote attacker to c…
- CVE-2001-0708Denicomp REXECD 1.05 and earlier allows a remote attacker to…
- CVE-2001-0709Microsoft IIS 4.0 and before, when installed on a FAT partit…
- CVE-2001-0710NetBSD 1.5 and earlier and FreeBSD 4.3 and earlier allows a …
- CVE-2001-0711Cisco IOS 11.x and 12.0 with ATM support allows attackers to…
- CVE-2001-0712The rendering engine in Internet Explorer determines the MIM…
- CVE-2001-0714Sendmail before 8.12.1, without the RestrictQueueRun option …
- CVE-2001-0715Sendmail before 8.12.1, without the RestrictQueueRun option …
- CVE-2001-0716Citrix MetaFrame 1.8 Server with Service Pack 3, and XP Serv…
- CVE-2001-0717Format string vulnerability in ToolTalk database server rpc.…
- CVE-2001-0718Vulnerability in (1) Microsoft Excel 2002 and earlier and (2…
- CVE-2001-0719Buffer overflow in Microsoft Windows Media Player 6.4 allows…
Are you affected by CVE-2001-0713?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
