Unrated severityNVD Advisory· Published Oct 11, 2002· Updated Apr 16, 2026
CVE-2002-1165
CVE-2002-1165
Description
Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows attackers to bypass the intended restrictions of smrsh by inserting additional commands after (1) "||" sequences or (2) "/" characters, which are not properly filtered or verified.
Affected products
12cpe:2.3:a:sendmail:sendmail:8.12.0:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:sendmail:sendmail:8.12.0:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.12.1:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.12.2:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.12.3:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.12.4:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.12.5:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.12.6:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- www.securityfocus.com/bid/5845nvdExploitPatchVendor Advisory
- www.sendmail.org/smrsh.adv.txtnvdExploitPatchVendor Advisory
- www.iss.net/security_center/static/10232.phpnvdVendor Advisory
- ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-023.txt.ascnvd
- distro.conectiva.com.br/atualizacoes/nvd
- marc.infonvd
- secunia.com/advisories/7826nvd
- www.mandriva.com/security/advisoriesnvd
- www.redhat.com/support/errata/RHSA-2003-073.htmlnvd
News mentions
0No linked articles in our index yet.