Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privileges via a large value in the 'category' part of debugger (-d) command line arguments, which is interpreted as a negative number.
| Product | Vendor | Version |
|---|---|---|
| n/a | n/a | <= * |
| n/a | n/a | < 2.2.1 |