nmh Buffer Overflow Vulnerability
BID:1018
Info
nmh Buffer Overflow Vulnerability
| Bugtraq ID: | 1018 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Feb 28 2000 12:00AM |
| Updated: | Feb 28 2000 12:00AM |
| Credit: | This vulnerability was posted to the Bugtraq mailing list on February 29, 2000 by [email protected] (Ruud de Rooij) |
| Vulnerable: |
Turbolinux Turbolinux 6.0.2 Turbolinux Turbolinux 4.4 Turbolinux Turbolinux 4.2 Turbolinux Turbolinux 3.5 b2 Redhat nmh 1.0 -2.sparc Redhat nmh 1.0 -2.i386 Redhat nmh 1.0 -2.alpha Redhat nmh 0.27 -8.sparc Redhat nmh 0.27 -8.i386 Redhat nmh 0.27 -8.alpha Redhat nmh 0.27 -1.sparc Redhat nmh 0.27 -1.i386 Redhat nmh 0.27 -1.alpha nmh nmh 1.0.2 |
| Not Vulnerable: |
Redhat nmh 1.0.3 -6x.sparc Redhat nmh 1.0.3 -6x.i386 Redhat nmh 1.0.3 -6x.alpha Redhat nmh 1.0.3 -5x.sparc Redhat nmh 1.0.3 -5x.i386 Redhat nmh 1.0.3 -5x.alpha nmh nmh 1.0.3 |
Discussion
nmh Buffer Overflow Vulnerability
It has been reported that a buffer overrun exists in versions 1.0.2 and prior of the nmh mailer. It is possible for a would be attacker to craft a MIME message in such a way as to cause the mhshow command to execute arbitary code when viewed. This could potentially lead to remote access for an attacker on the machine the mail is being read on.
Exact details on this vulnerability were not made public.
It has been reported that a buffer overrun exists in versions 1.0.2 and prior of the nmh mailer. It is possible for a would be attacker to craft a MIME message in such a way as to cause the mhshow command to execute arbitary code when viewed. This could potentially lead to remote access for an attacker on the machine the mail is being read on.
Exact details on this vulnerability were not made public.
Exploit / POC
nmh Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
nmh Buffer Overflow Vulnerability
Redhat nmh 0.27 -1.i386
Redhat nmh 0.27 -8.sparc
Redhat nmh 0.27 -8.i386
Redhat nmh 0.27 -1.alpha
Redhat nmh 0.27 -8.alpha
Redhat nmh 0.27 -1.sparc
Redhat nmh 1.0 -2.sparc
Redhat nmh 1.0 -2.alpha
Redhat nmh 1.0 -2.i386
nmh nmh 1.0.2
Redhat nmh 0.27 -1.i386
-
Red Hat Inc. 5.2 i386 nmh-1.0.3-5x.i386.rpm
ftp://updates.redhat.com/5.2/i386/nmh-1.0.3-5x.i386.rpm
Redhat nmh 0.27 -8.sparc
-
Red Hat Inc. 6.1 sparc nmh-1.0.3-6x.sparc.rpm
ftp://updates.redhat.com/6.1/sparc/nmh-1.0.3-6x.sparc.rpm
Redhat nmh 0.27 -8.i386
-
Red Hat Inc. 6.1 i386 nmh-1.0.3-6x.i386.rpm
ftp://updates.redhat.com/6.1/i386/nmh-1.0.3-6x.i386.rpm
Redhat nmh 0.27 -1.alpha
-
Red Hat Inc. 5.2 alpha nmh-1.0.3-5x.alpha.rpm
ftp://updates.redhat.com/5.2/alpha/nmh-1.0.3-5x.alpha.rpm
Redhat nmh 0.27 -8.alpha
-
Red Hat Inc. 6.1 alpha nmh-1.0.3-6x.alpha.rpm
ftp://updates.redhat.com/6.1/alpha/nmh-1.0.3-6x.alpha.rpm
Redhat nmh 0.27 -1.sparc
-
Red Hat Inc. 5.2 sparc nmh-1.0.3-5x.sparc.rpm
ftp://updates.redhat.com/5.2/sparc/nmh-1.0.3-5x.sparc.rpm
Redhat nmh 1.0 -2.sparc
-
Red Hat Inc. 6.1 sparc nmh-1.0.3-6x.sparc.rpm
ftp://updates.redhat.com/6.1/sparc/nmh-1.0.3-6x.sparc.rpm
Redhat nmh 1.0 -2.alpha
-
Red Hat Inc. 6.1 alpha nmh-1.0.3-6x.alpha.rpm
ftp://updates.redhat.com/6.1/alpha/nmh-1.0.3-6x.alpha.rpm
Redhat nmh 1.0 -2.i386
-
Red Hat Inc. 6.1 i386 nmh-1.0.3-6x.i386.rpm
ftp://updates.redhat.com/6.1/i386/nmh-1.0.3-6x.i386.rpm
nmh nmh 1.0.2
-
nmh nmh 1.0.3
ftp://ftp.mhost.com/pub/nmh/nmh-1.0.3.tar.gz
References
nmh Buffer Overflow Vulnerability
References:
References: