Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to cause a denial of service (data loss) by (1) setting a high initial message hop count option (-h), which causes Sendmail to drop queue entries, (2) via the -qR option, or (3) via the -qS option.
Link | Tags |
---|---|
ftp://patches.sgi.com/support/free/security/advisories/20011101-01-I | vendor advisory |
http://razor.bindview.com/publish/advisories/adv_sm812.html | patch vendor advisory |