CVE-2002-1165
EPSS 1.1%
描述
Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows attackers to bypass the intended restrictions of smrsh by inserting additional commands after (1) "||" sequences or (2) "/" characters, which are not properly filtered or verified.
如何修補 CVE-2002-1165
要修補 CVE-2002-1165,請將受影響套件升級到下列已修補版本。
- Debian/sendmail—升級至 8.12.3-5 或更新版本
CVE-2002-1165 正在被利用嗎?
低 — EPSS 為 1.1%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 8.12.3-5