SCO OpenServer POP Server Buffer Overflow Vulnerability
BID:156
Info
SCO OpenServer POP Server Buffer Overflow Vulnerability
| Bugtraq ID: | 156 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 1998 12:00AM |
| Updated: | Jul 13 1998 12:00AM |
| Credit: | This vulnerability was posted to the Bugtraq mailing list on July 15, 1998 by Vit Andrusevich <[email protected]>. It included a fully functional exploit. Fix information was posted by Bela Lubkin <[email protected]> on July 16, 1998. |
| Vulnerable: |
SCO Open Server 5.0.4 SCO Open Server 5.0.3 SCO Open Server 5.0.2 SCO Open Server 5.0.1 SCO Open Server 5.0 |
| Not Vulnerable: | |
Solution / Fix
SCO OpenServer POP Server Buffer Overflow Vulnerability
Solution:
SCO released patches to this problem on July 16, 1998. They are available in the SCO Security Enhancements directory at ftp://ftp.sco.com/SSE. This patch applies to SCO Open Servers versions 5.0.0 through 5.0.4.
An alternate fix would be to obtain the latest version of Qualcomm's pop server, available at ftp://ftp.qualcomm.com.
Solution:
SCO released patches to this problem on July 16, 1998. They are available in the SCO Security Enhancements directory at ftp://ftp.sco.com/SSE. This patch applies to SCO Open Servers versions 5.0.0 through 5.0.4.
An alternate fix would be to obtain the latest version of Qualcomm's pop server, available at ftp://ftp.qualcomm.com.