HP DTMail Attachment Argument Buffer Overflow Vulnerability
BID:20580
Info
HP DTMail Attachment Argument Buffer Overflow Vulnerability
| Bugtraq ID: | 20580 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 17 2006 12:00AM |
| Updated: | Oct 23 2006 09:38PM |
| Credit: | Discovery of this vulnerability is credited to Adriel T. Desautels of Netragard, L.L.C. |
| Vulnerable: |
HP Tru64 5.1 B-2 PK4 (BL25) HP Tru64 5.1 B-2 PK4 HP Tru64 5.1 B PK3 (BL24) HP Tru64 5.1 B PK3 HP Tru64 5.1 A PK6 (BL24) HP Tru64 5.1 A PK6 HP Tru64 4.0 G PK4 (BL22) HP Tru64 4.0 G PK4 HP Tru64 4.0 F PK8 (BL22) HP Tru64 4.0 F PK8 HP HP-UX B.11.23 HP HP-UX B.11.11 HP HP-UX B.11.00 HP dtmail 5.1b |
| Not Vulnerable: | |
Discussion
HP DTMail Attachment Argument Buffer Overflow Vulnerability
A buffer-overflow vulnerability occurs in dtmail when processing an overly long argument to the application's '-a' option. The problem occurs because the application fails to perform sufficient boundary checks when copying a filename argument into an internal memory buffer.
An attacker may exploit this buffer overflow to execute arbitrary code. In the case where an application has the 'setgid' bit turned on, a compromise in the context of a member of the group 'mail' is possible.
This vulnerability resides in dtmail version 5.1b; other versions might also be affected.
A buffer-overflow vulnerability occurs in dtmail when processing an overly long argument to the application's '-a' option. The problem occurs because the application fails to perform sufficient boundary checks when copying a filename argument into an internal memory buffer.
An attacker may exploit this buffer overflow to execute arbitrary code. In the case where an application has the 'setgid' bit turned on, a compromise in the context of a member of the group 'mail' is possible.
This vulnerability resides in dtmail version 5.1b; other versions might also be affected.
Exploit / POC
HP DTMail Attachment Argument Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
HP DTMail Attachment Argument Buffer Overflow Vulnerability
Solution:
HP has released updates to address this issue. Please see the referenced advisories for details on obtaining and applying the appropriate updates.
HP HP-UX B.11.23
HP HP-UX B.11.00
HP Tru64 4.0 G PK4
HP Tru64 4.0 F PK8
HP Tru64 5.1 A PK6
HP Tru64 5.1 B PK3
HP Tru64 5.1 B-2 PK4
Solution:
HP has released updates to address this issue. Please see the referenced advisories for details on obtaining and applying the appropriate updates.
HP HP-UX B.11.23
-
HP PHSS_35435
http://itrc.hp.com
HP HP-UX B.11.00
-
HP PHSS_35433
http://itrc.hp.com
HP Tru64 4.0 G PK4
-
HP T64KIT1000911-V40GB22-ES-20060928
http://www2.itrc.hp.com/service/patch/patchDetail.do?patchid=T64KIT100 0911-V40GB22-ES-20060928
HP Tru64 4.0 F PK8
-
HP DUXKIT1000913-V40FB22-ES-20060928
http://www2.itrc.hp.com/service/patch/patchDetail.do?patchid=DUXKIT100 0913-V40FB22-ES-20060928
HP Tru64 5.1 A PK6
-
HP T64KIT1000916-V51AB24-ES-20060929
http://www2.itrc.hp.com/service/patch/patchDetail.do?patchid=T64KIT100 0916-V51AB24-ES-20060929
HP Tru64 5.1 B PK3
-
HP T64KIT1000912-V51BB26-ES-20060928
http://www2.itrc.hp.com/service/patch/patchDetail.do?patchid=T64KIT100 0912-V51BB26-ES-20060928
HP Tru64 5.1 B-2 PK4
-
HP T64KIT1000908-V51BB25-ES-20060928
http://www2.itrc.hp.com/service/patch/patchDetail.do?patchid=T64KIT100 0908-V51BB25-ES-20060928
References
HP DTMail Attachment Argument Buffer Overflow Vulnerability
References:
References:
- [Full-disclosure] [NETRAGARD-20060810 SECURITY ADVISORY] [HP Tru64 dtmail Unchec (Roman Medina-Heigl Hernandez)
- dtmail man page (Hewlett Packard)
- Netragard, L.L.C Advisory - dtmail (Netragard, L.L.C)