VYPR
Unrated severityNVD Advisory· Published Oct 11, 2002· Updated Apr 16, 2026

CVE-2002-1165

CVE-2002-1165

Description

Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows attackers to bypass the intended restrictions of smrsh by inserting additional commands after (1) "||" sequences or (2) "/" characters, which are not properly filtered or verified.

Affected products

12
  • cpe:2.3:a:sendmail:sendmail:8.12.0:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:sendmail:sendmail:8.12.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sendmail:sendmail:8.12.1:*:*:*:*:*:*:*
    • cpe:2.3:a:sendmail:sendmail:8.12.2:*:*:*:*:*:*:*
    • cpe:2.3:a:sendmail:sendmail:8.12.3:*:*:*:*:*:*:*
    • cpe:2.3:a:sendmail:sendmail:8.12.4:*:*:*:*:*:*:*
    • cpe:2.3:a:sendmail:sendmail:8.12.5:*:*:*:*:*:*:*
    • cpe:2.3:a:sendmail:sendmail:8.12.6:*:*:*:*:*:*:*
  • NetBSD/NetBSD5 versions
    cpe:2.3:o:netbsd:netbsd:1.5:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:o:netbsd:netbsd:1.5:*:*:*:*:*:*:*
    • cpe:2.3:o:netbsd:netbsd:1.5.1:*:*:*:*:*:*:*
    • cpe:2.3:o:netbsd:netbsd:1.5.2:*:*:*:*:*:*:*
    • cpe:2.3:o:netbsd:netbsd:1.5.3:*:*:*:*:*:*:*
    • cpe:2.3:o:netbsd:netbsd:1.6:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.