header-logo
Suggest Exploit
vendor:
Sendmail
by:
qaaz
7,2
CVSS
HIGH
Local Exploit
N/A
CWE
Product Name: Sendmail
Affected Version From: 1.21
Affected Version To: 1.21
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2005

XMail 1.21 ‘sendmail’ local exploit (ret-into-libc)

This exploit is for XMail 1.21 'sendmail' which is a local exploit that yields uid root or gid mail. It is written in C and uses the ret-into-libc technique. It creates a mailroot directory and gets the libc base address. It then gets the system() and file() addresses and writes a file. It then exploits the vulnerability and waits for a shell. Finally, it executes the shell.

Mitigation:

Update to the latest version of XMail 1.21 'sendmail'
Source

Exploit-DB raw data: