Sun DtMail Local Command Line Format String Vulnerability
BID:11027
Info
Sun DtMail Local Command Line Format String Vulnerability
| Bugtraq ID: | 11027 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0800 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 24 2004 12:00AM |
| Updated: | Jul 12 2009 06:17AM |
| Credit: | iDEFENSE Labs is credited with discovering this vulnerability. |
| Vulnerable: |
Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun DtMail Avaya CMS Server 12.0 Avaya CMS Server 11.0 Avaya CMS Server 9.0 |
| Not Vulnerable: | |
Discussion
Sun DtMail Local Command Line Format String Vulnerability
Reportedly Sun DtMail is affected by a local format string vulnerability in its processing of command line arguments. This issue is due to a failure to securely implement a formatted string function.
Successful exploitation of this issue will allow an attacker to execute arbitrary code on the affected computer with the privileges of the mail group.
NOTE: This issue is reported by Sun to be a buffer overflow vulnerability, however iDEFENSE has defined it as a format string vulnerability. It is currently believed that these issues are the same, and that some misclassification has occurred. If there is more than a single issue a new BID will be created.
Avaya Call Management System (CMS) is affected by this issue as well.
Reportedly Sun DtMail is affected by a local format string vulnerability in its processing of command line arguments. This issue is due to a failure to securely implement a formatted string function.
Successful exploitation of this issue will allow an attacker to execute arbitrary code on the affected computer with the privileges of the mail group.
NOTE: This issue is reported by Sun to be a buffer overflow vulnerability, however iDEFENSE has defined it as a format string vulnerability. It is currently believed that these issues are the same, and that some misclassification has occurred. If there is more than a single issue a new BID will be created.
Avaya Call Management System (CMS) is affected by this issue as well.
Exploit / POC
Sun DtMail Local Command Line Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Sun DtMail Local Command Line Format String Vulnerability
Solution:
Sun has released Sun Alert 5762 along with patches dealing with this issue. Please see the referenced web advisory for more information.
Avaya has released advisory ASA-2005-110 to identify affected versions of CMS. Patches will be released in the near future. Please see the referenced Avaya advisory for more information.
Sun Solaris 9_x86
Sun Solaris 8_x86
Sun Solaris 8_sparc
Sun Solaris 9
Solution:
Sun has released Sun Alert 5762 along with patches dealing with this issue. Please see the referenced web advisory for more information.
Avaya has released advisory ASA-2005-110 to identify affected versions of CMS. Patches will be released in the near future. Please see the referenced Avaya advisory for more information.
Sun Solaris 9_x86
Sun Solaris 8_x86
Sun Solaris 8_sparc
Sun Solaris 9
References
Sun DtMail Local Command Line Format String Vulnerability
References:
References: